2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34499MEDIUM6.9AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten...
CVE-2025-13668MEDIUM6.7A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.
CVE-2025-66590CRITICAL9.8In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker t...
CVE-2025-66589CRITICAL9.1In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to...
CVE-2025-66588CRITICAL9.8In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by a...
CVE-2025-66587Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-66586HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp...
CVE-2025-66585HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup...
CVE-2025-66584Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-66429HIGH8.8An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow...
CVE-2025-64702MEDIUM5.3quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al...
CVE-2025-55816MEDIUM6.1HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
CVE-2025-14538LOW3.5A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCust...
CVE-2025-14537CRITICAL9.8A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some ...
CVE-2025-14293MEDIUM6.5The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ...
CVE-2025-13664MEDIUM6.7A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.
CVE-2025-13663MEDIUM6.7Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus t...
CVE-2025-55184HIGH7.5A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1...
CVE-2025-55183MEDIUM5.3An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 1...
CVE-2025-36938MEDIUM6.8In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead t...
CVE-2025-36937CRITICAL9.8In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect b...
CVE-2025-36936HIGH7.8In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. Thi...
CVE-2025-36935HIGH7.8In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This ...
CVE-2025-36934HIGH7.4In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co...
CVE-2025-36932HIGH7.8In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now