2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52434HIGH7.5Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc...
CVE-2025-28244HIGH8.8Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain...
CVE-2025-28243HIGH8An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component.
CVE-2025-53020HIGH7.5Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Ser...
CVE-2025-49812HIGH7.4In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows...
CVE-2025-49630HIGH7.5In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63...
CVE-2025-27889HIGH8.8Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint...
CVE-2025-7365HIGH7.1A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account du...
CVE-2025-46835HIGH8.5Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository ...
CVE-2025-46334HIGH8.6Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of...
CVE-2025-44251HIGH7.5Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.
CVE-2025-27614HIGH8.6Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that wit...
CVE-2025-7425HIGH7.8A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory m...
CVE-2025-7424HIGH7.5A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which ...
CVE-2025-7407HIGH8.8A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of...
CVE-2025-5040HIGH7.8A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A mal...
CVE-2025-5037HIGH7.8A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerabi...
CVE-2025-32990HIGH8.2A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certt...
CVE-2025-6948HIGH8An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 1...
CVE-2025-5023HIGH7.1Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB”...
CVE-2025-38348HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: p54: prevent buffer-overflow in p54_rx_eeprom...
CVE-2025-38346HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix UAF when lookup kallsym after ftrace di...
CVE-2025-38342HIGH7.1In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node...
CVE-2025-38341HIGH7.8In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: avoid double free when failing to DMA-m...
CVE-2025-38340HIGH7.1In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUn...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now