2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20783MEDIUM6.7In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20782MEDIUM6.7In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20781HIGH7.8In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20780HIGH7.8In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20779HIGH7In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege...
CVE-2025-20778HIGH7.8In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20762MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2025-20761MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2025-20760MEDIUM6.5In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de...
CVE-2025-15385CRITICAL9.8Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication...
CVE-2025-15364HIGH7.3The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up ...
CVE-2025-69197MEDIUM6.5Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip...
CVE-2025-68954MEDIUM5.4Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co...
CVE-2025-15444CRITICAL9.8Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1...
CVE-2025-69230MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu...
CVE-2025-69229MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o...
CVE-2025-69228HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques...
CVE-2025-69227HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an i...
CVE-2025-69225MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser...
CVE-2025-69226MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta...
CVE-2025-69224MEDIUM6.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python ...
CVE-2025-69223HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo...
CVE-2025-68953HIGH7.5Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests...
CVE-2025-68456CRITICAL9.1Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u...
CVE-2025-68455HIGH7.2Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now