2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54463HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-52931HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-44004HIGH7.2Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance whic...
CVE-2025-25231HIGH7.5Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga...
CVE-2025-8859HIGH8.8A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionali...
CVE-2025-8863HIGH7YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
CVE-2025-8862HIGH7YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag config...
CVE-2025-8846HIGH7.8A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser....
CVE-2025-8845HIGH7.8A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the fi...
CVE-2025-8672HIGH7.8MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permission...
CVE-2025-8843HIGH7.8A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file ou...
CVE-2025-8842HIGH7.8A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of ...
CVE-2025-8839HIGH8.8A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/...
CVE-2025-8837HIGH7.8A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/j...
CVE-2025-8747HIGH7.8A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attac...
CVE-2025-8833HIGH8.8A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue a...
CVE-2025-8832HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnera...
CVE-2025-8831HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the ...
CVE-2025-8830HIGH8.8A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by ...
CVE-2025-8829HIGH8.8A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by ...
CVE-2025-8828HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is ...
CVE-2025-8827HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affect...
CVE-2025-27577HIGH7in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
CVE-2025-27128HIGH7.8in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
CVE-2025-25278HIGH7in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now