2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-20963HIGH7.8Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to w...
CVE-2025-20957HIGH7.8Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary act...
CVE-2025-0669HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOI...
CVE-2025-32405HIGH7.5An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that...
CVE-2025-32402HIGH7.5An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that...
CVE-2025-32400HIGH7.5An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic...
CVE-2025-32399HIGH7.5An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t...
CVE-2025-32398HIGH7.5A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices ...
CVE-2025-32397HIGH7.5An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic...
CVE-2025-32396HIGH7.5An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic...
CVE-2025-4335HIGH8.8The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and...
CVE-2025-3921HIGH8.2The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-3852HIGH8.8The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2....
CVE-2025-0856HIGH7.3The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ...
CVE-2025-4372HIGH8.8Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap...
CVE-2025-47420HIGH8.7266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.2153...
CVE-2025-0853HIGH7.5The PGS Core plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'save_header_builder' ...
CVE-2025-46573HIGH8.6passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ...
CVE-2025-0649HIGH7.5Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbound...
CVE-2025-46820HIGH7.1phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom wo...
CVE-2025-46815HIGH8The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API...
CVE-2025-30165HIGH8vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, ...
CVE-2025-22476HIGH8Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Element...
CVE-2025-22478HIGH8.1Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit...
CVE-2025-22477HIGH8.8Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now