2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40087HIGH7.5In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles ...
CVE-2025-62230HIGH7.3A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The soft...
CVE-2025-62229HIGH7.3A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error ...
CVE-2025-62231HIGH7.3A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCom...
CVE-2025-9954HIGH7.5Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0....
CVE-2025-12466HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect ...
CVE-2025-12082HIGH7.5Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects Civ...
CVE-2025-61725HIGH7.5The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsi...
CVE-2025-61723HIGH7.5The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affe...
CVE-2025-58188HIGH7.5Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that as...
CVE-2025-58187HIGH7.5Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with ...
CVE-2025-54546HIGH7.5On affected platforms, restricted users could use SSH port forwarding to access host-internal services
CVE-2025-54545HIGH7.8On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privil...
CVE-2025-54459HIGH8.7Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd witho...
CVE-2025-9871HIGH7.8Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local ...
CVE-2025-9870HIGH7.8Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability all...
CVE-2025-9869HIGH7.8Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local at...
CVE-2025-11465HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2025-11464HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-11463HIGH7.8Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2025-10934HIGH7.8GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-10925HIGH7.8GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2025-10924HIGH7.8GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to...
CVE-2025-10923HIGH7.8GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ...
CVE-2025-10922HIGH7.8GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now