2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49537HIGH7.9ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements ...
CVE-2025-49536HIGH7.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2025-43582HIGH7.8Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res...
CVE-2025-7192HIGH8.8A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ss...
CVE-2025-53355HIGH7.5MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulne...
CVE-2025-7190HIGH8.8A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affect...
CVE-2025-48385HIGH8.6Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-48384HIGH8Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-37102HIGH7.2An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Acces...
CVE-2025-7189HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this iss...
CVE-2025-7188HIGH8.8A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an ...
CVE-2025-30312HIGH7.8Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary...
CVE-2025-0928HIGH8.8In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent bina...
CVE-2025-7187HIGH8.8A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function ...
CVE-2025-7186HIGH8.8A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unkno...
CVE-2025-49753HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49744HIGH7Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-49742HIGH7.8Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
CVE-2025-49740HIGH8.8Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a ...
CVE-2025-49739HIGH8.8Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to eleva...
CVE-2025-49738HIGH7.8Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to ...
CVE-2025-49737HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an...
CVE-2025-49735HIGH8.1Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-49733HIGH7.8Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2025-49732HIGH7.8Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now