2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53681HIGH7.2An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab...
CVE-2025-53680MEDIUM6.7An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul...
CVE-2025-46311HIGH7.5An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and...
CVE-2025-43524HIGH8.8An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS S...
CVE-2025-65719CRITICAL9.8An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user...
CVE-2025-36515MEDIUM5.4Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may...
CVE-2025-36510MEDIUM6.8Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver...
CVE-2025-35991MEDIUM5.6Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat...
CVE-2025-35990HIGH8.8Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring ...
CVE-2025-35979MEDIUM6.8Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio...
CVE-2025-35969MEDIUM5.4Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3...
CVE-2025-27723MEDIUM6.8Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke...
CVE-2025-70842MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The f...
CVE-2025-12659HIGH7.8Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could...
CVE-2025-6577CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So...
CVE-2025-40949CRITICAL9.1A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40948MEDIUM6.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40947HIGH7.7A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40946HIGH8.3A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6....
CVE-2025-40833HIGH8.7The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ...
CVE-2025-65418HIGH7.5docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary...
CVE-2025-65417MEDIUM6.1docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page...
CVE-2025-65416MEDIUM6.3docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
CVE-2025-65415MEDIUM5.4docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic...
CVE-2025-63750Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-21709. Reason: This record is a duplicate of CVE-2026-...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now