2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-51846HIGH8.7CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade o...
CVE-2025-14576HIGH7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio...
CVE-2025-50328HIGH7.3A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th...
CVE-2025-67223HIGH7.5The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w...
CVE-2025-48431HIGH7.5Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach...
CVE-2025-69428HIGH7.5An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi...
CVE-2025-69689HIGH8.8The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dial...
CVE-2025-70994HIGH7.3Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent...
CVE-2025-36074HIGH7.2IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to m...
CVE-2025-31958HIGH8.2HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise wh...
CVE-2025-14362HIGH7.3The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin...
CVE-2025-13826HIGH8.2Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu...
CVE-2025-65104HIGH7.5Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect...
CVE-2025-46607HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-46606HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-46605HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-36568HIGH7.8Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio...
CVE-2025-15624HIGH7.5Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID...
CVE-2025-15623HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau...
CVE-2025-54502HIGH7.5Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker...
CVE-2025-14868HIGH8.8The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr...
CVE-2025-63029HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar...
CVE-2025-67841HIGH7.5Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
CVE-2025-40899HIGH8.9A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat...
CVE-2025-40897HIGH8.1An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now