2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-51675HIGH7.5An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c...
CVE-2025-61164HIGH7.5Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
CVE-2025-61162HIGH7.5Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req...
CVE-2025-56798HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows ...
CVE-2025-29419HIGH7.1CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
CVE-2025-26238HIGH8.1In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
CVE-2025-26237HIGH8.1D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b...
CVE-2025-36940HIGH8.8Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U...
CVE-2025-68825HIGH7.5HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta...
CVE-2025-63080HIGH8.5Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o...
CVE-2025-52182HIGH7.5The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.
CVE-2025-15637HIGH8.1Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
CVE-2025-14601HIGH8.6An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execu...
CVE-2025-36255HIGH8.8IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe...
CVE-2025-36254HIGH7.4IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attac...
CVE-2025-14603HIGH8.8The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable ...
CVE-2025-9210HIGH8.1Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows ...
CVE-2025-27772HIGH7.4UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `...
CVE-2025-27771HIGH7.4UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `...
CVE-2025-27770HIGH7.4UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `...
CVE-2025-27621HIGH7.7UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U...
CVE-2025-7639HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta...
CVE-2025-59323HIGH8.4CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partition...
CVE-2025-59322HIGH7.5CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v...
CVE-2025-59319HIGH7.2CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now