2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56241HIGH7.5Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the ...
CVE-2025-52907HIGH8.8Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect...
CVE-2025-48869HIGH7.5Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res...
CVE-2025-20352HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa...
CVE-2025-20327HIGH7.7A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to...
CVE-2025-20315HIGH8.6A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau...
CVE-2025-20312HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe...
CVE-2025-20311HIGH7.4A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co...
CVE-2025-20160HIGH8.1A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo...
CVE-2025-56816HIGH8.8Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack...
CVE-2025-56815HIGH7.1Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses ...
CVE-2025-20334HIGH8.8A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that...
CVE-2025-10892HIGH8.8Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co...
CVE-2025-10891HIGH8.8Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co...
CVE-2025-10502HIGH8.8Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit ...
CVE-2025-10501HIGH8.8Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap ...
CVE-2025-10500HIGH8.8Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co...
CVE-2025-47329HIGH7.8Memory corruption while handling invalid inputs in application info setup.
CVE-2025-47328HIGH7.5Transient DOS while processing power control requests with invalid antenna or stream values.
CVE-2025-47327HIGH7.8Memory corruption while encoding the image data.
CVE-2025-47326HIGH7.5Transient DOS while handling command data during power control processing.
CVE-2025-47318HIGH7.5Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-47317HIGH7.8Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
CVE-2025-47316HIGH7.8Memory corruption due to double free when multiple threads race to set the timestamp store.
CVE-2025-47315HIGH7.8Memory corruption while handling repeated memory unmap requests from guest VM.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now