2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48997HIGH8.7Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1...
CVE-2025-48950HIGH8.8MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution p...
CVE-2025-23102HIGH8.8An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Doub...
CVE-2025-5511HIGH7.5A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affec...
CVE-2025-30167HIGH7.3Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to versio...
CVE-2025-23107HIGH8.6An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou...
CVE-2025-25022HIGH8.8IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all...
CVE-2025-25021HIGH7.2IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all...
CVE-2025-23103HIGH8.6An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou...
CVE-2025-5503HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the func...
CVE-2025-36564HIGH7.8Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal...
CVE-2025-5498HIGH7.2A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the...
CVE-2025-46154HIGH8.4Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
CVE-2025-4435HIGH7.5When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members wo...
CVE-2025-4330HIGH7.5Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the...
CVE-2025-4138HIGH7.5Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the...
CVE-2025-5492HIGH8.8A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnera...
CVE-2025-4392HIGH7.2The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2025-31359HIGH8.8A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers...
CVE-2025-46355HIGH7.3Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY...
CVE-2025-21479HIGH8.6Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-31710HIGH8.4In engineermode service, there is a possible command injection due to improper input validation. This could lead to loca...
CVE-2025-27038HIGH7.5Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVE-2025-27031HIGH7.8memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
CVE-2025-27029HIGH7.5Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now