2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7417HIGH8.8A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability i...
CVE-2025-7416HIGH8.8A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function from...
CVE-2025-53637HIGH8Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_reques...
CVE-2025-7415HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the f...
CVE-2025-7414HIGH8.8A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function f...
CVE-2025-3947HIGH8.2The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). A...
CVE-2025-3946HIGH8.2The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the comp...
CVE-2025-2521HIGH8.6The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Acce...
CVE-2025-7413HIGH8.8A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part ...
CVE-2025-7412HIGH8.8A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is ...
CVE-2025-53634HIGH7.5Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes h...
CVE-2025-53630HIGH8.9llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in g...
CVE-2025-53629HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests usi...
CVE-2025-53628HIGH8.8cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not ...
CVE-2025-53506HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial set...
CVE-2025-34098HIGH7.1A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper...
CVE-2025-34097HIGH8.6An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of upl...
CVE-2025-34093HIGH7.5An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible ove...
CVE-2025-2520HIGH7.5The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications....
CVE-2025-53625HIGH8.7The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with variou...
CVE-2025-53542HIGH7.7Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script ...
CVE-2025-53503HIGH7.8Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to u...
CVE-2025-52837HIGH7.8Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalat...
CVE-2025-52521HIGH7.1Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou...
CVE-2025-52520HIGH7.5For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now