2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71251HIGH7.5In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service w...
CVE-2025-66369HIGH7.5An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 128...
CVE-2025-61669MEDIUM6.1Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query pa...
CVE-2025-52206MEDIUM4.7ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
CVE-2025-42611MEDIUM6.5RouterOS provides various services that rely on correct verification of client and server certificates to secure confide...
CVE-2025-13618CRITICAL9.8The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th...
CVE-2025-67796HIGH8.1IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access t...
CVE-2025-47408HIGH7.8Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
CVE-2025-47407HIGH7Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level...
CVE-2025-47406MEDIUM5.5Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47405HIGH7.8Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
CVE-2025-47404HIGH7.8Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modif...
CVE-2025-47403HIGH7.5Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireles...
CVE-2025-47401HIGH7.5Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-70071MEDIUM5.9An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA...
CVE-2025-70072MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter:...
CVE-2025-70070MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet...
CVE-2025-13605CRITICAL9.33onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to exec...
CVE-2025-70069HIGH7.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMes...
CVE-2025-70067CRITICAL9.8Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiM...
CVE-2025-58074HIGH8.8A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-...
CVE-2025-14320CRITICAL9.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management...
CVE-2025-14726MEDIUM6.5The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of ...
CVE-2025-12993——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67968. Reason: This candidate is a ...
CVE-2025-8903——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2052. Reason: This candidate is a r...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now