2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66208CRITICAL9.8Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing ...
CVE-2025-66032CRITICAL9.8Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor...
CVE-2025-63402MEDIUM5.5An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code vi...
CVE-2025-63401MEDIUM5.5Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to...
CVE-2025-50360HIGH8.4A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2...
CVE-2025-33211HIGH7.5NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified ...
CVE-2025-33208HIGH8.8NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path....
CVE-2025-33201HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exc...
CVE-2025-13992MEDIUM4.7Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta...
CVE-2025-12819HIGH8.1Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to ...
CVE-2025-12084MEDIUM5.3When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_ca...
CVE-2025-66478Rejected reason: This CVE is a duplicate of CVE-2025-55182.
CVE-2025-64763MEDIUM5.3Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is c...
CVE-2025-64527MEDIUM6.5Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes w...
CVE-2025-64443CRITICAL9.6MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gatew...
CVE-2025-66431HIGH7.8WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr...
CVE-2025-65843HIGH7.7Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generati...
CVE-2025-65842MEDIUM5.1The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege esc...
CVE-2025-65841MEDIUM6.2Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Suppor...
CVE-2025-62686MEDIUM6.2A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin...
CVE-2025-55076MEDIUM6.2A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Instal...
CVE-2025-54326HIGH7.5An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardwa...
CVE-2025-54065HIGH7.9GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and...
CVE-2025-53965MEDIUM5.3An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 220...
CVE-2025-34319CRITICAL9.3TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now