2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-37840HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixe...
CVE-2025-37839HIGH7.8In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal em...
CVE-2025-4377HIGH8.3Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnera...
CVE-2025-3462HIGH8.4"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici...
CVE-2025-4462HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. This issue affects...
CVE-2025-4459HIGH8.8A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected...
CVE-2025-4458HIGH8.8A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affec...
CVE-2025-3713HIGH8.7The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.21...
CVE-2025-3712HIGH8.7The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.21...
CVE-2025-4455HIGH7.3A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects s...
CVE-2025-4446HIGH8.6A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the...
CVE-2025-4440HIGH8.6A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the funct...
CVE-2025-47733HIGH7.5Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over ...
CVE-2025-33072HIGH7.5Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
CVE-2025-29827HIGH8.8Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
CVE-2025-27578HIGH8.7Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM fil...
CVE-2025-1331HIGH7.8IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t...
CVE-2025-1330HIGH7.8IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on ...
CVE-2025-1329HIGH7.8IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t...
CVE-2025-4098HIGH8.4Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could a...
CVE-2025-1948HIGH7.5In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 set...
CVE-2025-26847HIGH7.5An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
CVE-2025-45846HIGH8.8ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in th...
CVE-2025-45845HIGH8.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet...
CVE-2025-45844HIGH8.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now