2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10200HIGH8.8Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti...
CVE-2025-8696HIGH7.5If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for t...
CVE-2025-57392HIGH7.8BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone...
CVE-2025-55976HIGH8.4Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us...
CVE-2025-50892HIGH7.8The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges f...
CVE-2025-57642HIGH7.2A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she...
CVE-2025-59045HIGH7.1Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion...
CVE-2025-43888HIGH7.8Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information in...
CVE-2025-43887HIGH7.8Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerab...
CVE-2025-43885HIGH7.8Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele...
CVE-2025-43725HIGH7.8Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default P...
CVE-2025-20340HIGH7.4A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthen...
CVE-2025-56466HIGH7.5Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.
CVE-2025-56413HIGH8.8OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary comman...
CVE-2025-56407HIGH8.8A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function ...
CVE-2025-56406HIGH7.5An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary comma...
CVE-2025-56405HIGH7.5An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the ...
CVE-2025-56404HIGH7.5An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the...
CVE-2025-10231HIGH7.8An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstanc...
CVE-2025-7718HIGH8.8The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation ...
CVE-2025-10225HIGH8.7Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in...
CVE-2025-10224HIGH7.1Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on...
CVE-2025-10223HIGH8.1Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windo...
CVE-2025-40979HIGH7DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this...
CVE-2025-10215HIGH7.8DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now