2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59784HIGH7.22N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl...
CVE-2025-59783HIGH7.2API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al...
CVE-2025-71238HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ...
CVE-2025-70341HIGH7.8Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
CVE-2025-66168HIGH8.8WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  follow...
CVE-2025-14480HIGH7.5IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-13688HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-13687HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-13686HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-36363HIGH7.5IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru...
CVE-2025-14604HIGH7.8IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow...
CVE-2025-13616HIGH7.5IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ...
CVE-2025-69765HIGH7.5Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus...
CVE-2025-67840HIGH7.2Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil...
CVE-2025-63912HIGH7.5Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da...
CVE-2025-63911HIGH7.2Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti...
CVE-2025-63910HIGH7.2An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al...
CVE-2025-63909HIGH7.8Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4....
CVE-2025-62817HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ...
CVE-2025-66680HIGH7.1An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele...
CVE-2025-66363HIGH7.5An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit...
CVE-2025-62814HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ...
CVE-2025-64736HIGH7.1An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma...
CVE-2025-52365HIGH7.8A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ...
CVE-2025-15595HIGH7.8Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now