2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47913HIGH7.5SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the cl...
CVE-2025-36251CRITICAL9.8IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to ex...
CVE-2025-36250CRITICAL9.8IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a...
CVE-2025-36236CRITICAL9.1IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a...
CVE-2025-36096HIGH8.1IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which...
CVE-2025-13131HIGH8.5A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\...
CVE-2025-13130HIGH8.5A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra...
CVE-2025-64746MEDIUM5.4Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does...
CVE-2025-64745MEDIUM6.1Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) ...
CVE-2025-64744LOW3.5OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming ...
CVE-2025-4619MEDIUM6.6A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reb...
CVE-2025-47222MEDIUM6.5A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any...
CVE-2025-47221MEDIUM5.3An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME...
CVE-2025-47220MEDIUM5.3A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTO...
CVE-2025-64726HIGH7.3Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by...
CVE-2025-64709CRITICAL9.9Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerabili...
CVE-2025-60702MEDIUM6.5A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `sys...
CVE-2025-60699MEDIUM6.5A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `globa...
CVE-2025-60679HIGH8.8A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210...
CVE-2025-59840HIGH8.1Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2025-55810MEDIUM6.8A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmwa...
CVE-2025-46370MEDIUM5.5Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low pr...
CVE-2025-46369HIGH7.8Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability...
CVE-2025-46368MEDIUM5.5Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability...
CVE-2025-46367HIGH7.8Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Ac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now