2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61724MEDIUM5.3The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the n...
CVE-2025-61723HIGH7.5The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affe...
CVE-2025-58189MEDIUM5.3When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols...
CVE-2025-58188HIGH7.5Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that as...
CVE-2025-58187HIGH7.5Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with ...
CVE-2025-58186MEDIUM5.3Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By s...
CVE-2025-58185MEDIUM5.3Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-58183MEDIUM4.3tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A mal...
CVE-2025-54549MEDIUM5.9Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgra...
CVE-2025-54548MEDIUM4.3On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user...
CVE-2025-54547MEDIUM5.3On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) mult...
CVE-2025-54546HIGH7.5On affected platforms, restricted users could use SSH port forwarding to access host-internal services
CVE-2025-54545HIGH7.8On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privil...
CVE-2025-47912MEDIUM5.3The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component ...
CVE-2025-11428Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-61959MEDIUM6.9Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebR...
CVE-2025-54459HIGH8.7Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd witho...
CVE-2025-9871HIGH7.8Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local ...
CVE-2025-9870HIGH7.8Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability all...
CVE-2025-9869HIGH7.8Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local at...
CVE-2025-60320MEDIUM6.7memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (...
CVE-2025-11466MEDIUM4.9Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote atta...
CVE-2025-11465HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2025-11464HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-11463HIGH7.8Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now