2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12428HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write v...
CVE-2025-63288HIGH7.5In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.
CVE-2025-47773MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-47286HIGH7.2Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by ...
CVE-2025-43723HIGH7.5Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or ...
CVE-2025-43079MEDIUM6.3The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported ve...
CVE-2025-12967HIGH8.6An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low pr...
CVE-2025-63835HIGH8.8A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in...
CVE-2025-63834MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exi...
CVE-2025-63497HIGH7.1The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System v...
CVE-2025-63457HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. Th...
CVE-2025-63456HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. ...
CVE-2025-63455HIGH7.5Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus...
CVE-2025-63147HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlI...
CVE-2025-63154HIGH7.5TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urld...
CVE-2025-63153HIGH7.5TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode...
CVE-2025-63152HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternPa...
CVE-2025-46430HIGH7.3Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulne...
CVE-2025-8768Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12020. Reason: This candidate is a ...
CVE-2025-63712HIGH8.8Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete...
CVE-2025-63711HIGH7.1A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an ...
CVE-2025-63710MEDIUM6.5The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery ...
CVE-2025-63709MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text...
CVE-2025-12480CRITICAL9.1Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init...
CVE-2025-64690Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to interna...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now