2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59144HIGH8.8debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after ...
CVE-2025-59143HIGH8.8color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for col...
CVE-2025-59142HIGH8.8color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-...
CVE-2025-59141HIGH8.8simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken...
CVE-2025-59140HIGH8.8backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken ...
CVE-2025-10472HIGH7.5A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download...
CVE-2025-10471HIGH8.8A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaCon...
CVE-2025-10203HIGH8.5Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar...
CVE-2025-57248HIGH7.3A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu fil...
CVE-2025-43793HIGH7.5Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202...
CVE-2025-10491HIGH7.8The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t...
CVE-2025-6202HIGH7.1Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Inte...
CVE-2025-56710HIGH7.3A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Ma...
CVE-2025-50944HIGH8.8An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes ...
CVE-2025-50110HIGH8.8An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, th...
CVE-2025-3025HIGH7.3Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local use...
CVE-2025-39804HIGH7.8In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm64/poly1305: Fix register corruption...
CVE-2025-39803HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from uf...
CVE-2025-39802HIGH7.8In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm/poly1305: Fix register corruption i...
CVE-2025-59358HIGH7.5The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kuber...
CVE-2025-10443HIGH8.8A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function fo...
CVE-2025-10442HIGH8.8A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /...
CVE-2025-10431HIGH8.8A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of t...
CVE-2025-10430HIGH8.8A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown fun...
CVE-2025-10429HIGH8.8A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Affected by this vulnerability is a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now