2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-46405HIGH8.7When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management M...
CVE-2025-55154HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-54382HIGH8.8Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R...
CVE-2025-32451HIGH8.8A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A sp...
CVE-2025-8907HIGH7A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the comp...
CVE-2025-8671HIGH7.5A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architect...
CVE-2025-48989HIGH7.5Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack...
CVE-2025-54464HIGH7This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device f...
CVE-2025-8914HIGH7.5Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote at...
CVE-2025-8912HIGH8.7Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated...
CVE-2025-8909HIGH7.1Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attacker...
CVE-2025-55345HIGH8.8Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file o...
CVE-2025-8761HIGH7.7A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the co...
CVE-2025-6184HIGH8.8The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection ...
CVE-2025-8901HIGH8.8Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds...
CVE-2025-8882HIGH8.8Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage...
CVE-2025-8880HIGH8.8Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox...
CVE-2025-8879HIGH8.8Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit...
CVE-2025-4410HIGH7.5A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit ...
CVE-2025-4277HIGH7.5Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM l...
CVE-2025-4276HIGH7.5UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SM...
CVE-2025-54232HIGH7.8Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in...
CVE-2025-54231HIGH7.8Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in...
CVE-2025-54230HIGH7.8Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in...
CVE-2025-54229HIGH7.8Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now