2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58150HIGH8.8Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables...
CVE-2025-57283HIGH7.8The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile...
CVE-2025-59901HIGH8.5Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoin...
CVE-2025-59895HIGH7.5Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulne...
CVE-2025-59894HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59893HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59892HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59891HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-26386HIGH7.1Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iST...
CVE-2025-14386HIGH8.8The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ...
CVE-2025-7740HIGH8.8Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attack...
CVE-2025-40537HIGH7.5SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat...
CVE-2025-14610HIGH7.2The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a...
CVE-2025-67645HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-55292HIGH8.2Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by t...
CVE-2025-33234HIGH7.8NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulner...
CVE-2025-14911HIGH7.1User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overf...
CVE-2025-69421HIGH7.5Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i...
CVE-2025-69420HIGH7.5Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE unio...
CVE-2025-69419HIGH7.4Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16...
CVE-2025-55102HIGH7.5A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A special...
CVE-2025-55095HIGH7The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W...
CVE-2025-15467HIGH8.8Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg...
CVE-2025-41727HIGH7.8A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per...
CVE-2025-41726HIGH8.8A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now