2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48798HIGH7.3A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special...
CVE-2025-48797HIGH7.3A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been...
CVE-2025-48796HIGH7.3A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.AN...
CVE-2025-5272HIGH7.3Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption a...
CVE-2025-5270HIGH7.5In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed...
CVE-2025-5269HIGH8.1Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption a...
CVE-2025-5268HIGH8.1Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bu...
CVE-2025-5262HIGH7.5A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder ...
CVE-2025-5244HIGH7.8A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the funct...
CVE-2025-5117HIGH8.8The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of ...
CVE-2025-41653HIGH7.5An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionalit...
CVE-2025-41650HIGH7.5An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt...
CVE-2025-41649HIGH7.5An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer...
CVE-2025-5232HIGH7.2A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1...
CVE-2025-5228HIGH8.8A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function...
CVE-2025-5227HIGH7.3A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown proces...
CVE-2025-48828HIGH8.1Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t...
CVE-2025-26211HIGH8.8Gibbon before 29.0.00 allows CSRF.
CVE-2025-5226HIGH7.3A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknow...
CVE-2025-5204HIGH7.8A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the fun...
CVE-2025-5203HIGH7.8A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this ...
CVE-2025-5202HIGH7.8A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by th...
CVE-2025-5201HIGH7.8A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is ...
CVE-2025-5200HIGH7.8A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects th...
CVE-2025-23395HIGH7.8Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now