2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61857HIGH8.4An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlie...
CVE-2025-61856HIGH8.4A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earl...
CVE-2025-52625HIGH7.5A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose cre...
CVE-2025-11189HIGH7.3The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, ...
CVE-2025-11188HIGH7.3The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued...
CVE-2025-52634HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
CVE-2025-52632HIGH7.5A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-52630HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-30001HIGH7.3Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from...
CVE-2025-21069HIGH7.1Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to ac...
CVE-2025-21068HIGH7.1Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to ac...
CVE-2025-21067HIGH7.1Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers ...
CVE-2025-21066HIGH7.1Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-o...
CVE-2025-21062HIGH7.8Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to rep...
CVE-2025-21058HIGH7.3Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attack...
CVE-2025-21055HIGH7.5Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access...
CVE-2025-21053HIGH7.8Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local a...
CVE-2025-21052HIGH7.8Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 ...
CVE-2025-21051HIGH7.8Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at...
CVE-2025-21048HIGH7.8Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary c...
CVE-2025-61871HIGH8.4NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w...
CVE-2025-61779HIGH8.7Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing ...
CVE-2025-61773HIGH8.1pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte...
CVE-2025-61602HIGH7.5BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 a...
CVE-2025-61601HIGH7.5BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now