2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47286HIGH7.2Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by ...
CVE-2025-43723HIGH7.5Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or ...
CVE-2025-12967HIGH8.6An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low pr...
CVE-2025-63835HIGH8.8A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in...
CVE-2025-63497HIGH7.1The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System v...
CVE-2025-63457HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. Th...
CVE-2025-63456HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. ...
CVE-2025-63455HIGH7.5Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus...
CVE-2025-63147HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlI...
CVE-2025-63154HIGH7.5TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urld...
CVE-2025-63153HIGH7.5TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode...
CVE-2025-63152HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternPa...
CVE-2025-46430HIGH7.3Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulne...
CVE-2025-63712HIGH8.8Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete...
CVE-2025-63711HIGH7.1A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an ...
CVE-2025-64685HIGH7.5In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
CVE-2025-64684HIGH7.5In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
CVE-2025-64683HIGH7.5In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
CVE-2025-64457HIGH7In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
CVE-2025-64456HIGH7.8In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
CVE-2025-12405HIGH7.7An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Loo...
CVE-2025-12409HIGH7.3A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sour...
CVE-2025-12397HIGH7.6A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject mal...
CVE-2025-12155HIGH7.1A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows...
CVE-2025-41731HIGH7.4A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now