2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54282HIGH7.8Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Heap-based Buffer Overflow vulnerability that cou...
CVE-2025-54281HIGH7.8Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Use After Free vulnerability that could result in...
CVE-2025-54276HIGH7.8Substance3D - Modeler versions 1.22.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra...
CVE-2025-54280HIGH7.8Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54274HIGH7.8Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could ...
CVE-2025-54273HIGH7.8Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-33182HIGH7.6NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause...
CVE-2025-60536HIGH7.5An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Servi...
CVE-2025-57618HIGH7.3A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the s...
CVE-2025-23356HIGH8.4NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might...
CVE-2025-60535HIGH7.3A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to e...
CVE-2025-59502HIGH7.5Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over ...
CVE-2025-59494HIGH7.8Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-59295HIGH8.8Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
CVE-2025-59292HIGH8.2External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate...
CVE-2025-59291HIGH8.2External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate...
CVE-2025-59290HIGH7.8Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59289HIGH7Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59285HIGH7Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-59282HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows ...
CVE-2025-59281HIGH7.8Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to ...
CVE-2025-59278HIGH7.8Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat...
CVE-2025-59277HIGH7.8Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat...
CVE-2025-59275HIGH7.8Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat...
CVE-2025-59261HIGH7Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to eleva...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now