2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6232HIGH8.5An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at...
CVE-2025-6231HIGH8.5An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at...
CVE-2025-4657HIGH8.4A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Le...
CVE-2025-3753HIGH7.8A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS dist...
CVE-2025-23270HIGH7.1NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exp...
CVE-2025-23267HIGH8.5NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could ...
CVE-2025-1700HIGH7.1A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that coul...
CVE-2025-0886HIGH8.5An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe...
CVE-2025-7472HIGH7.5A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a loc...
CVE-2025-53817HIGH7.57-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to vers...
CVE-2025-53816HIGH7.57-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to m...
CVE-2025-7747HIGH8.8A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle...
CVE-2025-23263HIGH7.6NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es...
CVE-2025-7338HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1...
CVE-2025-54062HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54061HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54060HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54058HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-53946HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-53909HIGH7.2mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vul...
CVE-2025-1713HIGH7.5When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream brid...
CVE-2025-5344HIGH8.5Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.blu...
CVE-2025-7735HIGH8.7The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a...
CVE-2025-34130HIGH8.7An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2....
CVE-2025-34129HIGH8.7A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now