2025 CVE Vulnerabilities

45,155 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57615HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new ...
CVE-2025-57614HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in t...
CVE-2025-57613HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input...
CVE-2025-57612HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() ...
CVE-2025-54599HIGH7.5The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover,...
CVE-2025-9784HIGH7.5A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering ab...
CVE-2025-2413HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypa...
CVE-2025-52550HIGH7.2E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge ma...
CVE-2025-52547HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacke...
CVE-2025-52545HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which retur...
CVE-2025-52544HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta...
CVE-2025-52543HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for ...
CVE-2025-46810HIGH8.5A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traef...
CVE-2025-2414HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypa...
CVE-2025-9573HIGH8.6The ns_backup extension through 13.0.2 for TYPO3 allows command injection.
CVE-2025-41690HIGH7.4A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)...
CVE-2025-9815HIGH7.8A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o...
CVE-2025-9813HIGH8.8A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /gofo...
CVE-2025-9812HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file...
CVE-2025-9805HIGH7.5A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unk...
CVE-2025-58178HIGH7.8SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In version...
CVE-2025-57808HIGH8.1ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP...
CVE-2025-9801HIGH8.1A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affec...
CVE-2025-3586HIGH7.2In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10,...
CVE-2025-57799HIGH8.7StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the Stre...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now