2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-20393CRITICAL10A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure...
CVE-2025-44005CRITICAL10An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without ...
CVE-2025-67895CRITICAL9.8Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you in...
CVE-2025-59374CRITICAL9.8"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modificat...
CVE-2025-14700CRITICAL9.9An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authentica...
CVE-2025-53619CRITICAL9.1An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ...
CVE-2025-53618CRITICAL9.1An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ...
CVE-2025-48429CRITICAL9.1An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A sp...
CVE-2025-65834CRITICAL9.8Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT projec...
CVE-2025-68270CRITICAL9.9The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours...
CVE-2025-62864CRITICAL9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-62863CRITICAL9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-46295CRITICAL9.8Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass...
CVE-2025-33210CRITICAL9NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod...
CVE-2025-63414CRITICAL10A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to a...
CVE-2025-50401CRITICAL9.8Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa...
CVE-2025-50398CRITICAL9.8Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa...
CVE-2025-37164CRITICAL9.8A remote code execution issue exists in HPE OneView.
CVE-2025-68315CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free...
CVE-2025-68301CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix fragment overflow handling in RX...
CVE-2025-68285CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_a...
CVE-2025-68284CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in ...
CVE-2025-65319CRITICAL9.1When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system with...
CVE-2025-65318CRITICAL9.1When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system witho...
CVE-2025-68263CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_requ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now