2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11756HIGH8.8Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised t...
CVE-2025-11460HIGH8.8Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code vi...
CVE-2025-11458HIGH8.1Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of boun...
CVE-2025-64178HIGH8.9Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to dow...
CVE-2025-11211HIGH7.5Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out...
CVE-2025-11209HIGH8.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to ...
CVE-2025-11206HIGH7.1Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a...
CVE-2025-11205HIGH8.8Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the...
CVE-2025-64173HIGH7.5Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation ...
CVE-2025-52881HIGH7.5runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and ...
CVE-2025-12790HIGH7.4A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Ma...
CVE-2025-12489HIGH7.8evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local at...
CVE-2025-12486HIGH8.8Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2025-52565HIGH7.5runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1....
CVE-2025-34239HIGH7.2Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.app...
CVE-2025-12490HIGH8.8Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-63551HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in...
CVE-2025-60541HIGH7.3A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows ...
CVE-2025-31133HIGH7.8runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, ...
CVE-2025-27919HIGH8.2An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can ...
CVE-2025-27917HIGH7.5An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7....
CVE-2025-27916HIGH7.5An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection be...
CVE-2025-63589HIGH7.1A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are no...
CVE-2025-63588HIGH7.1An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attack...
CVE-2025-63560HIGH7.5An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now