2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9479MEDIUM4.3Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap ...
CVE-2025-13107MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-13102MEDIUM4.3Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote atta...
CVE-2025-13097MEDIUM5.4Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentiall...
CVE-2025-64753MEDIUM6.5grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document c...
CVE-2025-64752MEDIUM6.5grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist instal...
CVE-2025-64749MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messa...
CVE-2025-64748MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11...
CVE-2025-64747MEDIUM5.5Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vul...
CVE-2025-64746MEDIUM5.4Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does...
CVE-2025-64745MEDIUM6.1Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) ...
CVE-2025-4619MEDIUM6.6A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reb...
CVE-2025-47222MEDIUM6.5A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any...
CVE-2025-47221MEDIUM5.3An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME...
CVE-2025-47220MEDIUM5.3A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTO...
CVE-2025-60702MEDIUM6.5A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `sys...
CVE-2025-60699MEDIUM6.5A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `globa...
CVE-2025-55810MEDIUM6.8A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmwa...
CVE-2025-46370MEDIUM5.5Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low pr...
CVE-2025-46368MEDIUM5.5Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability...
CVE-2025-46362MEDIUM5.5Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability....
CVE-2025-60676MEDIUM6.5An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln...
CVE-2025-60675MEDIUM5.4A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the ti...
CVE-2025-60674MEDIUM6.8A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB...
CVE-2025-60673MEDIUM6.5An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now