2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52541HIGH7.3A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result...
CVE-2025-48503HIGH7.8A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation pote...
CVE-2025-57713HIGH7.5A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit th...
CVE-2025-57709HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-57707HIGH8.8An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been repor...
CVE-2025-52870HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-52869HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-52868HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-48725HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-48724HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-48723HIGH8.1A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th...
CVE-2025-30276HIGH8.8An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun...
CVE-2025-30269HIGH8.1A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attack...
CVE-2025-8099HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-10174HIGH8.3Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pr...
CVE-2025-15096HIGH8.8The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all...
CVE-2025-9986HIGH8.2Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information S...
CVE-2025-15440HIGH7.2The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Paramet...
CVE-2025-13651HIGH7.5Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Applicati...
CVE-2025-10913HIGH8.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cl...
CVE-2025-14541HIGH7.2The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin...
CVE-2025-29951HIGH7.3A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially ...
CVE-2025-29950HIGH7.1Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le...
CVE-2025-35998HIGH7.9Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) ...
CVE-2025-32008HIGH8.7Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applica...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now