2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1293HIGH8.2Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentiall...
CVE-2025-27092HIGH7.5GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path...
CVE-2025-25944HIGH7.3Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom...
CVE-2025-25943HIGH7.8Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2At...
CVE-2025-0624HIGH7.6A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copie...
CVE-2025-0893HIGH7.8Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.
CVE-2025-24965HIGH8.5crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could ...
CVE-2025-1426HIGH8.8Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially...
CVE-2025-1006HIGH8.8Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap...
CVE-2025-0999HIGH8.8Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit hea...
CVE-2025-1464HIGH7.3A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204....
CVE-2025-1075HIGH7.5Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (...
CVE-2025-1135HIGH7.2A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploi...
CVE-2025-1134HIGH7.2A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit...
CVE-2025-1133HIGH7.2A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit...
CVE-2025-1132HIGH8.8A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within th...
CVE-2025-1441HIGH8.8The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-1448HIGH7.3A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This ...
CVE-2025-27113HIGH7.5libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
CVE-2025-25475HIGH7.5A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial ...
CVE-2025-24928HIGH7.7libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To ...
CVE-2025-25895HIGH8An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulner...
CVE-2025-25894HIGH8An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters....
CVE-2025-25893HIGH8An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, e...
CVE-2025-26616HIGH7.5WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now