2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57283HIGH7.8The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile...
CVE-2025-59901HIGH8.5Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoin...
CVE-2025-59895HIGH7.5Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulne...
CVE-2025-59894HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59893HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59892HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59891HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-26386HIGH7.1Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iST...
CVE-2025-14386HIGH8.8The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ...
CVE-2025-7740HIGH8.8Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attack...
CVE-2025-40537HIGH7.5SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat...
CVE-2025-14610HIGH7.2The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a...
CVE-2025-67645HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-55292HIGH8.2Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by t...
CVE-2025-33234HIGH7.8NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulner...
CVE-2025-14911HIGH7.1User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overf...
CVE-2025-69421HIGH7.5Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i...
CVE-2025-69420HIGH7.5Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE unio...
CVE-2025-69419HIGH7.4Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16...
CVE-2025-55102HIGH7.5A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A special...
CVE-2025-55095HIGH7The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W...
CVE-2025-15467HIGH8.8Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg...
CVE-2025-41727HIGH7.8A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per...
CVE-2025-41726HIGH8.8A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the...
CVE-2025-30248HIGH8.9DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now