2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61735HIGH7.3Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5...
CVE-2025-61734HIGH7.5Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's ...
CVE-2025-61733HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin...
CVE-2025-54289HIGH8.1Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions...
CVE-2025-54286HIGH8.8Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and s...
CVE-2025-40645HIGH8.7Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensiti...
CVE-2025-9587HIGH8.6The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before usin...
CVE-2025-61692HIGH7.8VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, ...
CVE-2025-61691HIGH7.8VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted f...
CVE-2025-61690HIGH7.8KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted fil...
CVE-2025-58777HIGH7.8VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specia...
CVE-2025-58776HIGH8.4KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially ...
CVE-2025-58775HIGH8.4KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted...
CVE-2025-11182HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check...
CVE-2025-11020HIGH8.8An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex...
CVE-2025-61582HIGH7.5TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been ident...
CVE-2025-54811HIGH7.1OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a...
CVE-2025-23355HIGH7.8NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL hi...
CVE-2025-23297HIGH7.8NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attac...
CVE-2025-59538HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-...
CVE-2025-59537HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug...
CVE-2025-59531HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug...
CVE-2025-59150HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-59148HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-59147HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now