2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27446HIGH7.8Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listeni...
CVE-2025-7076HIGH8.8A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue...
CVE-2025-7075HIGH8.8A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vu...
CVE-2025-7074HIGH7.5A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/b...
CVE-2025-47227HIGH7.5In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset me...
CVE-2025-53603HIGH7.5In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo ...
CVE-2025-43711HIGH8.1Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upo...
CVE-2025-7070HIGH8.8A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulner...
CVE-2025-53366HIGH8.7The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi...
CVE-2025-53365HIGH8.7The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi...
CVE-2025-53485HIGH7.5SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user...
CVE-2025-53483HIGH8.8ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF toke...
CVE-2025-53481HIGH7.5Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Al...
CVE-2025-52496HIGH7.8Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may b...
CVE-2025-46733HIGH7.9OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2025-38233HIGH7.8In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatc...
CVE-2025-38230HIGH7.8In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent...
CVE-2025-38227HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of...
CVE-2025-38226HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: vivid: Change the siize of the composing sy...
CVE-2025-38224HIGH7.1In the Linux kernel, the following vulnerability has been resolved: can: kvaser_pciefd: refine error prone echo_skb_max...
CVE-2025-38221HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ext4: fix out of bounds punch offset Punching a ho...
CVE-2025-38216HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Restore context entry setup order for a...
CVE-2025-38212HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot ...
CVE-2025-38211HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after...
CVE-2025-38209HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now