2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-53536HIGH8.1Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker...
CVE-2025-20320HIGH7.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-7137HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This a...
CVE-2025-53531HIGH7.5WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT...
CVE-2025-53530HIGH7.5WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT...
CVE-2025-1351HIGH7IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another use...
CVE-2025-53376HIGH8.8Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an...
CVE-2025-53373HIGH8.9Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled ...
CVE-2025-52492HIGH7.5A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz,...
CVE-2025-48367HIGH7.5Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP p...
CVE-2025-32023HIGH7.8Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, ...
CVE-2025-26780HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che...
CVE-2025-6807HIGH7.5Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability a...
CVE-2025-6806HIGH7.5Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows r...
CVE-2025-6804HIGH7.5Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulner...
CVE-2025-6803HIGH7.5Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerabilit...
CVE-2025-6801HIGH7.5Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability ...
CVE-2025-6800HIGH7.5Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerabili...
CVE-2025-6799HIGH7.5Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability...
CVE-2025-6797HIGH7.5Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability...
CVE-2025-6796HIGH7.5Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability al...
CVE-2025-6795HIGH7.5Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability ...
CVE-2025-6714HIGH7.5MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete dat...
CVE-2025-6663HIGH7.8GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-5987HIGH8.1A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now