2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47408HIGH7.8Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
CVE-2025-47407HIGH7Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level...
CVE-2025-47406MEDIUM5.5Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47405HIGH7.8Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
CVE-2025-47404HIGH7.8Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modif...
CVE-2025-47403HIGH7.5Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireles...
CVE-2025-47401HIGH7.5Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-70071MEDIUM5.9An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA...
CVE-2025-70072MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter:...
CVE-2025-70070MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet...
CVE-2025-13605CRITICAL9.33onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to exec...
CVE-2025-70069HIGH7.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMes...
CVE-2025-70067CRITICAL9.8Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiM...
CVE-2025-58074HIGH8.8A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-...
CVE-2025-14320CRITICAL9.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management...
CVE-2025-14726MEDIUM6.5The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of ...
CVE-2025-12993Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67968. Reason: This candidate is a ...
CVE-2025-8903Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2052. Reason: This candidate is a r...
CVE-2025-52347HIGH7.8An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and Perf...
CVE-2025-69606MEDIUM6.1Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t...
CVE-2025-63548HIGH7.5An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet spe...
CVE-2025-63547HIGH7.5An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted pa...
CVE-2025-36335MEDIUM5.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo...
CVE-2025-36180HIGH7.5IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow a...
CVE-2025-36122MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now