2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-23397HIGH7.8A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualizat...
CVE-2025-23396HIGH7.8A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualizat...
CVE-2025-2176HIGH7.5A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim...
CVE-2025-27912HIGH8.8An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) E...
CVE-2025-2190HIGH8.1The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code inject...
CVE-2025-2174HIGH7.5A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability i...
CVE-2025-2173HIGH7.5A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_s...
CVE-2025-26705HIGH7.5Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro...
CVE-2025-26702HIGH7.5Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from...
CVE-2025-2169HIGH7.3The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execut...
CVE-2025-27434HIGH8.8Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicio...
CVE-2025-26661HIGH8.8Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels t...
CVE-2025-1828HIGH8.8Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptog...
CVE-2025-27610HIGH7.5Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack:...
CVE-2025-27910HIGH8tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This ...
CVE-2025-25907HIGH8.8tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulner...
CVE-2025-2137HIGH8.8Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memo...
CVE-2025-2136HIGH8.8Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit hea...
CVE-2025-2135HIGH8.8Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-1920HIGH8.8Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-27913HIGH7.5Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health...
CVE-2025-27616HIGH8.5Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions...
CVE-2025-27615HIGH8.2umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. Th...
CVE-2025-26696HIGH7Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an Ope...
CVE-2025-22603HIGH8.1AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now