2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9293HIGH8.1A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s...
CVE-2025-9292HIGH7.5A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u...
CVE-2025-40905HIGH7.3WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp...
CVE-2025-67433HIGH7.5A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a...
CVE-2025-67432HIGH7.5A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers t...
CVE-2025-69807HIGH7.5p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause...
CVE-2025-69806HIGH7.5p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get rel...
CVE-2025-63421HIGH7.8An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the...
CVE-2025-54519HIGH7.3A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resul...
CVE-2025-52533HIGH8.7Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and ...
CVE-2025-61880HIGH8.8In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
CVE-2025-61879HIGH7.7In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech...
CVE-2025-55210HIGH7.5FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, F...
CVE-2025-54756HIGH8.6BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo...
CVE-2025-70886HIGH7.5An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the ...
CVE-2025-15577HIGH7.5An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.Thi...
CVE-2025-46290HIGH7.5A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad...
CVE-2025-64487HIGH7.6Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability e...
CVE-2025-69871HIGH8.1A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the prom...
CVE-2025-70084HIGH7.5Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete...
CVE-2025-70083HIGH7.8An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and ...
CVE-2025-70029HIGH7.5An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl...
CVE-2025-65480HIGH8.8An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Te...
CVE-2025-65128HIGH8.1A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23....
CVE-2025-61969HIGH7Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now