2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10237HIGH8.4During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller fi...
CVE-2025-71330HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-71329HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-6254CRITICAL9.8The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8...
CVE-2025-8444MEDIUM6.4The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl...
CVE-2025-66281HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ...
CVE-2025-66280HIGH7.2An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a...
CVE-2025-66279HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-66273HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-62851MEDIUM4.4A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator ac...
CVE-2025-62850HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-66276CRITICAL9.8QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250...
CVE-2025-59382LOW1.2QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
CVE-2025-58468HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ...
CVE-2025-71319HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-55659MEDIUM6.5A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker...
CVE-2025-55658MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media...
CVE-2025-55657HIGH7.5A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack...
CVE-2025-55651MEDIUM5.5A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows...
CVE-2025-52293HIGH7.5A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo...
CVE-2025-52292HIGH7.5A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia...
CVE-2025-54509MEDIUM4Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg...
CVE-2025-67862MEDIUM6.7An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti...
CVE-2025-40808MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),...
CVE-2025-10263CRITICAL9.1Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now