2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-21486HIGH7.8Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
CVE-2025-21485HIGH7.8Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
CVE-2025-21480HIGH8.6Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21463HIGH7.5Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2025-4224HIGH7.2The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upl...
CVE-2025-5419HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl...
CVE-2025-5068HIGH8.8Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap co...
CVE-2025-48387HIGH8.7tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an ex...
CVE-2025-23105HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo...
CVE-2025-1051HIGH8.8Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent...
CVE-2025-27956HIGH7.5Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via th...
CVE-2025-20298HIGH8In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to...
CVE-2025-5036HIGH7.8A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A...
CVE-2025-48940HIGH7.2MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input...
CVE-2025-48866HIGH7.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ...
CVE-2025-45542HIGH7.3SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v...
CVE-2025-26396HIGH7.8The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escal...
CVE-2025-48990HIGH8.6NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`,...
CVE-2025-48957HIGH7.5AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions ...
CVE-2025-46807HIGH8.7A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file...
CVE-2025-29785HIGH7.5quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added i...
CVE-2025-1246HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace D...
CVE-2025-0819HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2025-0073HIGH7.8Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-5440HIGH8.8A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now