2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55651MEDIUM5.5A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows...
CVE-2025-52293HIGH7.5A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo...
CVE-2025-52292HIGH7.5A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia...
CVE-2025-54509MEDIUM4Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg...
CVE-2025-67862MEDIUM6.7An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti...
CVE-2025-40808MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),...
CVE-2025-10263CRITICAL9.1Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4...
CVE-2025-62858MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-71315MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk...
CVE-2025-12656LOW3.8The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de...
CVE-2025-71318CRITICAL9.8NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated ...
CVE-2025-71317CRITICAL9.8NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce...
CVE-2025-5090HIGH7.1CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil...
CVE-2025-5089HIGH7.1In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t...
CVE-2025-5088HIGH8.7An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi...
CVE-2025-59174HIGH7.1Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v...
CVE-2025-8873HIGH8.7On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st...
CVE-2025-71316CRITICAL9.8SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS...
CVE-2025-65640MEDIUM6.3Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5....
CVE-2025-69755HIGH8.2An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ...
CVE-2025-67448HIGH7.1The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not...
CVE-2025-67447CRITICAL9.8The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje...
CVE-2025-67446CRITICAL9.8Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u...
CVE-2025-62338LOW3.3HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized ...
CVE-2025-59874HIGH8.1HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now