2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-50202HIGH7.5Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local fil...
CVE-2025-4413HIGH8.8The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t...
CVE-2025-23252HIGH7.5The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A succ...
CVE-2025-49385HIGH7.1Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou...
CVE-2025-49384HIGH7.1Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou...
CVE-2025-49218HIGH7.8A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e...
CVE-2025-49215HIGH8.8A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e...
CVE-2025-49214HIGH8.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentic...
CVE-2025-49211HIGH7.8A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate pr...
CVE-2025-41413HIGH8.4Fuji Electric Smart Editor is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary cod...
CVE-2025-41388HIGH8.4Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitr...
CVE-2025-32412HIGH8.4Fuji Electric Smart Editor is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code...
CVE-2025-30641HIGH7.8A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow...
CVE-2025-30640HIGH7.8A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privile...
CVE-2025-49847HIGH8.8llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabu...
CVE-2025-30680HIGH7.1A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipul...
CVE-2025-30679HIGH7.5A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allo...
CVE-2025-30678HIGH7.5A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allo...
CVE-2025-49850HIGH8.4A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of pr...
CVE-2025-49849HIGH8.4An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper va...
CVE-2025-49848HIGH8.4An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper v...
CVE-2025-49158HIGH7.8An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to esc...
CVE-2025-49157HIGH7.8A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalat...
CVE-2025-49156HIGH7.8A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privil...
CVE-2025-49155HIGH8.8An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacke...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now