2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57797HIGH8.5Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vu...
CVE-2025-57820HIGH7.9Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object ...
CVE-2025-35114HIGH8.7Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The p...
CVE-2025-35113HIGH7.2Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticat...
CVE-2025-22412HIGH8.8In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could ...
CVE-2025-22411HIGH8.8In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. Th...
CVE-2025-22410HIGH8.4In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc...
CVE-2025-22409HIGH8.4In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This...
CVE-2025-22406HIGH8.4In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. ...
CVE-2025-22405HIGH8.4In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc...
CVE-2025-22404HIGH8.4In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This ...
CVE-2025-0093HIGH7.5In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission...
CVE-2025-0084HIGH8.8In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code e...
CVE-2025-0081HIGH7.5In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitiali...
CVE-2025-0080HIGH7.8In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overl...
CVE-2025-0079HIGH7.8In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error i...
CVE-2025-0078HIGH8.8In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to loca...
CVE-2025-50971HIGH7.5Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensiti...
CVE-2025-9478HIGH8.8Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap c...
CVE-2025-23315HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious dat...
CVE-2025-23314HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a...
CVE-2025-23313HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a...
CVE-2025-23312HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious da...
CVE-2025-23307HIGH7.8NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow...
CVE-2025-57803HIGH8.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now