2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24022HIGH8.5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is po...
CVE-2025-3600HIGH7.5In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may...
CVE-2025-3931HIGH7.8A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's ...
CVE-2025-4430HIGH8.6Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in ve...
CVE-2025-3834HIGH8.1Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU Histo...
CVE-2025-3833HIGH8.1Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MF...
CVE-2025-26864HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili...
CVE-2025-26795HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili...
CVE-2025-2875HIGH8.7CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of...
CVE-2025-26646HIGH8External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized att...
CVE-2025-43572HIGH7.8Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary...
CVE-2025-43571HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43570HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43569HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2025-43568HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43565HIGH8.4ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2025-43554HIGH7.8Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result...
CVE-2025-43553HIGH7.8Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that...
CVE-2025-43549HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43548HIGH7.8Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary...
CVE-2025-24308HIGH8.7Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privi...
CVE-2025-22892HIGH7.1Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 ...
CVE-2025-22843HIGH8.8Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow...
CVE-2025-21094HIGH8.7Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a p...
CVE-2025-20618HIGH8.3Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now