2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56588HIGH8.8Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module con...
CVE-2025-46205HIGH8.1A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to caus...
CVE-2025-10578HIGH7.8A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The ...
CVE-2025-60991HIGH8.8A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to exe...
CVE-2025-57393HIGH8.8A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2val...
CVE-2025-28357HIGH8.8A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supp...
CVE-2025-20371HIGH8.8In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-56515HIGH8.8File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fail...
CVE-2025-59684HIGH8.8DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
CVE-2025-52042HIGH8.2In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/re...
CVE-2025-52041HIGH8.2In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reco...
CVE-2025-52040HIGH8.2In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Inje...
CVE-2025-52039HIGH8.2In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_requ...
CVE-2025-10847HIGH8.4DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robo...
CVE-2025-39922HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix incorrect map used in eee linkmode inco...
CVE-2025-39917HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds dynptr write in bpf_crypto_c...
CVE-2025-39913HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdi...
CVE-2025-39911HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i40e: fix IRQ freeing in i40e_vsi_request_irq_msix ...
CVE-2025-39905HIGH7In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent p...
CVE-2025-39901HIGH7.1In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'com...
CVE-2025-39896HIGH7.8In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued...
CVE-2025-39891HIGH7.1In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to z...
CVE-2025-11226HIGH7ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.1...
CVE-2025-10538HIGH8.8An authentication bypass vulnerability exists in LG Innotek camera models LND7210 and LNV7210R. The vulnerability allows...
CVE-2025-24525HIGH8.7Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or dec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now