2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48503HIGH7.8A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation pote...
CVE-2025-57713HIGH7.5A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit th...
CVE-2025-57709HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-57707HIGH8.8An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been repor...
CVE-2025-52870HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-52869HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-52868HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-48725HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-48724HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-48723HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-30276HIGH8.8An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun...
CVE-2025-30269HIGH8.1A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attack...
CVE-2025-8099HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-10174HIGH8.3Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pr...
CVE-2025-15096HIGH8.8The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all...
CVE-2025-9986HIGH8.2Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information S...
CVE-2025-15440HIGH7.2The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Paramet...
CVE-2025-13651HIGH7.5Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Applicati...
CVE-2025-10913HIGH8.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cl...
CVE-2025-14541HIGH7.2The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin...
CVE-2025-29951HIGH7.3A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially ...
CVE-2025-29950HIGH7.1Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le...
CVE-2025-35998HIGH7.9Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) ...
CVE-2025-32008HIGH8.7Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applica...
CVE-2025-30513HIGH8.3Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adver...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now