2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11211HIGH7.5Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out...
CVE-2025-11210MEDIUM5.4Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced ...
CVE-2025-11209HIGH8.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to ...
CVE-2025-11208MEDIUM6.3Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a ...
CVE-2025-11207MEDIUM6.5Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform...
CVE-2025-11206HIGH7.1Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a...
CVE-2025-11205HIGH8.8Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the...
CVE-2025-64327MEDIUM5.3ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contai...
CVE-2025-64326LOW3.5Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project membe...
CVE-2025-64174MEDIUM4.8Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affecte...
CVE-2025-64173HIGH7.5Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation ...
CVE-2025-52881HIGH7.5runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and ...
CVE-2025-33110MEDIUM5.4IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-12790HIGH7.4A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Ma...
CVE-2025-12489HIGH7.8evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local at...
CVE-2025-12488CRITICAL9.8oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This...
CVE-2025-12487CRITICAL9.8oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This...
CVE-2025-12486HIGH8.8Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2025-52565HIGH7.5runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1....
CVE-2025-34247MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAc...
CVE-2025-34246MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.aja...
CVE-2025-34245MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsControl...
CVE-2025-34244MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDevic...
CVE-2025-34243MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetwo...
CVE-2025-34242MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxActio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now