2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59783HIGH7.2API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al...
CVE-2025-71238HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ...
CVE-2025-70341HIGH7.8Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
CVE-2025-66168HIGH8.8WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  follow...
CVE-2025-14480HIGH7.5IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-13688HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-13687HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-13686HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-36363HIGH7.5IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru...
CVE-2025-14604HIGH7.8IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow...
CVE-2025-13616HIGH7.5IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ...
CVE-2025-69765HIGH7.5Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus...
CVE-2025-67840HIGH7.2Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil...
CVE-2025-63912HIGH7.5Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da...
CVE-2025-63911HIGH7.2Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti...
CVE-2025-63910HIGH7.2An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al...
CVE-2025-63909HIGH7.8Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4....
CVE-2025-62817HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ...
CVE-2025-66680HIGH7.1An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele...
CVE-2025-66363HIGH7.5An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit...
CVE-2025-62814HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ...
CVE-2025-64736HIGH7.1An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma...
CVE-2025-52365HIGH7.8A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ...
CVE-2025-15595HIGH7.8Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
CVE-2025-12345HIGH8.8A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the functio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now