2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59837HIGH7.2Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy doma...
CVE-2025-40843HIGH7.8CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2025-12425HIGH7.8Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12423HIGH7.5Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19....
CVE-2025-60805HIGH7.5An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive...
CVE-2025-60800HIGH7.5Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce...
CVE-2025-60354HIGH7.5Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.
CVE-2025-54605HIGH7.5Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).
CVE-2025-54604HIGH7.5Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).
CVE-2025-60858HIGH7.5Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration...
CVE-2025-60349HIGH7.5An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E...
CVE-2025-56399HIGH8.8alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) ...
CVE-2025-61107HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p...
CVE-2025-61106HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p...
CVE-2025-61104HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tl...
CVE-2025-61103HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_l...
CVE-2025-34312HIGH8.8IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a...
CVE-2025-34311HIGH8.8IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a...
CVE-2025-53855HIGH7.8An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A spe...
CVE-2025-53814HIGH7.8A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially...
CVE-2025-1038HIGH7.5The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, al...
CVE-2025-1037HIGH7.5By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user l...
CVE-2025-1036HIGH8.7Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated us...
CVE-2025-40082HIGH7.1In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni...
CVE-2025-40081HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now