2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-25210HIGH8.2Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User ...
CVE-2025-22453HIGH7.5Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User ...
CVE-2025-20080HIGH8.2Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel...
CVE-2025-64157HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 throug...
CVE-2025-62676HIGH7.1An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet Forti...
CVE-2025-11004HIGH7.5The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. Th...
CVE-2025-7636HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security S...
CVE-2025-7347HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Trackin...
CVE-2025-6967HIGH8.7Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co....
CVE-2025-15570HIGH7.8A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file strea...
CVE-2025-15569HIGH7.3A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of t...
CVE-2025-40587HIGH7.6A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2)....
CVE-2025-11547HIGH7.8AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
CVE-2025-11142HIGH8.8The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executio...
CVE-2025-15314HIGH8.1Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
CVE-2025-15313HIGH7.1Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
CVE-2025-15310HIGH7.8Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
CVE-2025-15319HIGH7.8Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
CVE-2025-15316HIGH7.8Tanium addressed a local privilege escalation vulnerability in Tanium Server.
CVE-2025-15315HIGH7.8Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
CVE-2025-59023HIGH8.2Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2025-10465HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd...
CVE-2025-10463HIGH7.3Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Au...
CVE-2025-7799HIGH8.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor...
CVE-2025-66598HIGH7.5A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now