2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59473HIGH7.2SQL Injection vulnerability in the Structure for Admin authenticated user
CVE-2025-59472HIGH7.5A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min...
CVE-2025-59471HIGH7.5A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t...
CVE-2025-14459HIGH8.5A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu...
CVE-2025-14756HIGH8.8Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing...
CVE-2025-71178HIGH7.1Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins...
CVE-2025-67274HIGH7.5An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-...
CVE-2025-59107HIGH8.5Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The...
CVE-2025-59106HIGH8.8The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv...
CVE-2025-59105HIGH7With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta...
CVE-2025-59104HIGH7With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u...
CVE-2025-59101HIGH7.7Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on...
CVE-2025-59099HIGH8.8The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a ...
CVE-2025-59098HIGH8.7The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality...
CVE-2025-59094HIGH8.4A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy...
CVE-2025-59093HIGH8.5Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass...
CVE-2025-59092HIGH8.7An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th...
CVE-2025-27821HIGH7.3Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef...
CVE-2025-14316HIGH7.1The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting ...
CVE-2025-71162HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af...
CVE-2025-52026HIGH7.5An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend...
CVE-2025-67264HIGH7.8An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr...
CVE-2025-70986HIGH7.5Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access ...
CVE-2025-67230HIGH7.1Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere...
CVE-2025-71159HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now