2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11285HIGH8.8A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the...
CVE-2025-11284HIGH7.3A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vul...
CVE-2025-11277HIGH7.8A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternR...
CVE-2025-11275HIGH7.8A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function...
CVE-2025-39952HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: avoid buffer overflow in WID string...
CVE-2025-39951HIGH7.8In the Linux kernel, the following vulnerability has been resolved: um: virtio_uml: Fix use-after-free after put_device...
CVE-2025-39945HIGH7.8In the Linux kernel, the following vulnerability has been resolved: cnic: Fix use-after-free bugs in cnic_delete_task ...
CVE-2025-39944HIGH7.8In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix use-after-free bugs in otx2_sync_...
CVE-2025-39943HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_len...
CVE-2025-39939HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Fix memory corruption when using identi...
CVE-2025-39935HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ASoC: codec: sma1307: Fix memory corruption in sma1...
CVE-2025-9243HIGH8.1The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa...
CVE-2025-10751HIGH7.8MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi...
CVE-2025-61679HIGH7.7Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained...
CVE-2025-61673HIGH8.6Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent...
CVE-2025-10692HIGH7.1The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the S...
CVE-2025-54374HIGH8.8Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code...
CVE-2025-57714HIGH7.8An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain...
CVE-2025-54153HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-53595HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-52656HIGH7.6HCL MyXalytics: 6.6.  is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatica...
CVE-2025-47212HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-46819HIGH7.1Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-46818HIGH7.3Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-44014HIGH8.8An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now