2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-36906HIGH7.8In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer ov...
CVE-2025-36905HIGH7.8In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This ...
CVE-2025-36903HIGH7.8In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local e...
CVE-2025-36901HIGH8.8WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.
CVE-2025-36899HIGH8.4There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to ph...
CVE-2025-36898HIGH7.8There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of pri...
CVE-2025-36895HIGH7.5Information disclosure
CVE-2025-36894HIGH7.5In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no ...
CVE-2025-36892HIGH7.5Denial of service
CVE-2025-36891HIGH8.8Elevation of privilege
CVE-2025-36887HIGH7.8In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrec...
CVE-2025-2417HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication By...
CVE-2025-2411HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypas...
CVE-2025-58056HIGH7.5Netty is an asynchronous event-driven network application framework for development of maintainable high performance pro...
CVE-2025-57833HIGH8.1An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subjec...
CVE-2025-55748HIGH7.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2...
CVE-2025-9365HIGH8.4Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a speci...
CVE-2025-55162HIGH8.8Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In vers...
CVE-2025-56803HIGH8.4Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An atta...
CVE-2025-52494HIGH7.5Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o...
CVE-2025-45805HIGH7.6In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod...
CVE-2025-20336HIGH7.5A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C...
CVE-2025-20326HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ...
CVE-2025-20287HIGH8.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a...
CVE-2025-9959HIGH7.6Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sand...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now