2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1918HIGH8.8Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform ou...
CVE-2025-1916HIGH8.8Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a...
CVE-2025-1915HIGH8.1Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998....
CVE-2025-1914HIGH8.8Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memo...
CVE-2025-21092HIGH7.1GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in a...
CVE-2025-1961HIGH7.5A vulnerability has been found in SourceCodester Best Church Management Software 1.1 and classified as critical. Affecte...
CVE-2025-25426HIGH7.2yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
CVE-2025-1259HIGH7.7On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been ...
CVE-2025-1080HIGH7.8LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An addit...
CVE-2025-27111HIGH7.5Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sen...
CVE-2025-23368HIGH8.1A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multipl...
CVE-2025-1424HIGH8.6A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if the...
CVE-2025-1943HIGH8.2Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption a...
CVE-2025-1940HIGH7.1A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used...
CVE-2025-1937HIGH7.5Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7...
CVE-2025-1936HIGH7.3jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retri...
CVE-2025-1933HIGH7.6On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can poten...
CVE-2025-1932HIGH8.1An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Onl...
CVE-2025-1931HIGH7.5It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potenti...
CVE-2025-1930HIGH8.8On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the...
CVE-2025-1925HIGH7.5A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the functi...
CVE-2025-22225HIGH8.2VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trig...
CVE-2025-22224HIGH8.2VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds w...
CVE-2025-0360HIGH7.8During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi...
CVE-2025-1306HIGH8.8The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now