2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-25876HIGH7.2A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ...
CVE-2025-1546HIGH7.3A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critica...
CVE-2025-1403HIGH8.6Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted Q...
CVE-2025-26013HIGH8.2An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
CVE-2025-1538HIGH8.8A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function...
CVE-2025-1536HIGH7.3A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical...
CVE-2025-1535HIGH7.3A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This...
CVE-2025-1471HIGH7.8In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string co...
CVE-2025-0728HIGH7.5In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer un...
CVE-2025-0727HIGH7.5In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer un...
CVE-2025-0726HIGH7.5In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of s...
CVE-2025-27088HIGH8.2oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulner...
CVE-2025-25679HIGH8Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSe...
CVE-2025-22973HIGH7.5An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function ...
CVE-2025-27098HIGH7.5GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgra...
CVE-2025-27097HIGH7.5GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgra...
CVE-2025-0352HIGH8.7Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify reque...
CVE-2025-26618HIGH7Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirem...
CVE-2025-27091HIGH7.5OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding fun...
CVE-2025-26305HIGH8.2A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows at...
CVE-2025-26304HIGH8.2A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.
CVE-2025-0161HIGH7.8IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrar...
CVE-2025-21105HIGH7.8Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user...
CVE-2025-26856HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa...
CVE-2025-1492HIGH7.5Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now