2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-44018HIGH8.3A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft...
CVE-2025-40213HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set...
CVE-2025-10555HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer ...
CVE-2025-10554MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERI...
CVE-2025-13598Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-13541Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-12978MEDIUM5.4Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fa...
CVE-2025-12977CRITICAL9.1Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with netw...
CVE-2025-12972MEDIUM5.3Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option i...
CVE-2025-12970HIGH8.8The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit...
CVE-2025-12969MEDIUM6.5Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain c...
CVE-2025-11921HIGH8.5iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c...
CVE-2025-65998HIGH7.5Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though ...
CVE-2025-65503MEDIUM5.5Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via...
CVE-2025-65502MEDIUM4.3Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of s...
CVE-2025-65501MEDIUM4.3Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of...
CVE-2025-65500MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65499MEDIUM4.3Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause...
CVE-2025-65498MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65497MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65496MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65495HIGH7.5Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t...
CVE-2025-65494HIGH7.5NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker...
CVE-2025-65493HIGH7.5NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servic...
CVE-2025-41017MEDIUM6.9Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now