2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65127MEDIUM6.5A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot...
CVE-2025-13391MEDIUM5.8The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl...
CVE-2025-12474MEDIUM4.4A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This ...
CVE-2025-48518MEDIUM6.9Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially result...
CVE-2025-48508MEDIUM6Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual...
CVE-2025-68406MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-66278MEDIUM6.5A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th...
CVE-2025-66274MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-62856MEDIUM4.4A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac...
CVE-2025-62855MEDIUM4.4A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac...
CVE-2025-62854MEDIUM6.5An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain...
CVE-2025-62853MEDIUM6.5A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th...
CVE-2025-59386MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-58472MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an admini...
CVE-2025-58471MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-58470MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-58467MEDIUM6.5A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user acc...
CVE-2025-58466MEDIUM4.9A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a r...
CVE-2025-57711MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-57710MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-57708MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-54170MEDIUM6.5An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account...
CVE-2025-54169MEDIUM6.5An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accoun...
CVE-2025-54163MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an admin...
CVE-2025-54162MEDIUM4.9A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now