2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-30248HIGH8.9DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t...
CVE-2025-59473HIGH7.2SQL Injection vulnerability in the Structure for Admin authenticated user
CVE-2025-59472HIGH7.5A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min...
CVE-2025-59471HIGH7.5A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t...
CVE-2025-14459HIGH8.5A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu...
CVE-2025-14756HIGH8.8Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing...
CVE-2025-71178HIGH7.1Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins...
CVE-2025-67274HIGH7.5An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-...
CVE-2025-59107HIGH8.5Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The...
CVE-2025-59106HIGH8.8The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv...
CVE-2025-59105HIGH7With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta...
CVE-2025-59104HIGH7With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u...
CVE-2025-59101HIGH7.7Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on...
CVE-2025-59099HIGH8.8The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a ...
CVE-2025-59098HIGH8.7The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality...
CVE-2025-59094HIGH8.4A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy...
CVE-2025-59093HIGH8.5Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass...
CVE-2025-59092HIGH8.7An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th...
CVE-2025-27821HIGH7.3Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef...
CVE-2025-14316HIGH7.1The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting ...
CVE-2025-71162HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af...
CVE-2025-52026HIGH7.5An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend...
CVE-2025-67264HIGH7.8An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr...
CVE-2025-70986HIGH7.5Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access ...
CVE-2025-67230HIGH7.1Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now