2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9292HIGH7.5A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u...
CVE-2025-40905HIGH7.3WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp...
CVE-2025-67433HIGH7.5A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a...
CVE-2025-67432HIGH7.5A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers t...
CVE-2025-69807HIGH7.5p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause...
CVE-2025-69806HIGH7.5p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get rel...
CVE-2025-63421HIGH7.8An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the...
CVE-2025-54519HIGH7.3A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resul...
CVE-2025-52533HIGH8.7Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and ...
CVE-2025-61880HIGH8.8In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
CVE-2025-61879HIGH7.7In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech...
CVE-2025-55210HIGH7.5FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, F...
CVE-2025-54756HIGH8.6BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo...
CVE-2025-70886HIGH7.5An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the ...
CVE-2025-15577HIGH7.5An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.Thi...
CVE-2025-46290HIGH7.5A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad...
CVE-2025-64487HIGH7.6Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability e...
CVE-2025-69871HIGH8.1A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the prom...
CVE-2025-70084HIGH7.5Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete...
CVE-2025-70083HIGH7.8An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and ...
CVE-2025-70029HIGH7.5An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl...
CVE-2025-65480HIGH8.8An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Te...
CVE-2025-65128HIGH8.1A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23....
CVE-2025-61969HIGH7Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,...
CVE-2025-52541HIGH7.3A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now