2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-46814HIGH7.5FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr...
CVE-2025-2898HIGH8.8IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a ...
CVE-2025-0984HIGH8.2Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cr...
CVE-2025-46762HIGH8.1Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar...
CVE-2025-2011HIGH7.5The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter...
CVE-2025-27132HIGH7.8in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-21475HIGH7.8Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
CVE-2025-21470HIGH7.8Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
CVE-2025-21469HIGH7.8Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
CVE-2025-21468HIGH7.8Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to w...
CVE-2025-21467HIGH7.8Memory corruption while reading the FW response from the shared queue.
CVE-2025-21462HIGH7.8Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.
CVE-2025-21460HIGH7.8Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed cont...
CVE-2025-21459HIGH7.5Transient DOS while parsing per STA profile in ML IE.
CVE-2025-21453HIGH7.8Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential f...
CVE-2025-46589HIGH7.1Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will a...
CVE-2025-46588HIGH7.7Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will a...
CVE-2025-46585HIGH7Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability ...
CVE-2025-2802HIGH7.3The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,...
CVE-2025-3610HIGH8.8The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to...
CVE-2025-46728HIGH7.5cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enf...
CVE-2025-2509HIGH7.8Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address acc...
CVE-2025-46813HIGH7.5Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd...
CVE-2025-46731HIGH7.2Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch pri...
CVE-2025-45617HIGH7.5Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now