2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27828HIGH7.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1....
CVE-2025-27827HIGH7.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthen...
CVE-2025-6566HIGH7.5A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the f...
CVE-2025-6565HIGH8.8A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function ht...
CVE-2025-6436HIGH8.1Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption a...
CVE-2025-6435HIGH8.1If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not hav...
CVE-2025-6432HIGH8.6When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was inval...
CVE-2025-6426HIGH8.8The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affec...
CVE-2025-39205HIGH7.1A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol a...
CVE-2025-39204HIGH8.5A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface...
CVE-2025-39203HIGH7.1A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from ...
CVE-2025-39202HIGH8.1A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with lo...
CVE-2025-2403HIGH8.7A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in ...
CVE-2025-1718HIGH7.1An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device...
CVE-2025-6206HIGH7.5The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2025-3092HIGH7.5An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
CVE-2025-3091HIGH7.5An low privileged remote attacker in possession of the second factor for another user can login as that user without kno...
CVE-2025-3090HIGH8.2An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authent...
CVE-2025-2962HIGH7.5A denial-of-service issue in the dns implemenation could cause an infinite loop.
CVE-2025-41427HIGH8.8WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command...
CVE-2025-52568HIGH8.8NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issue...
CVE-2025-52566HIGH8.8llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer...
CVE-2025-52574HIGH7.5SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from ...
CVE-2025-52560HIGH8.8Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows...
CVE-2025-48466HIGH8.1Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now