2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-21163HIGH7.8Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res...
CVE-2025-21161HIGH7.8Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2025-21160HIGH7.8Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability th...
CVE-2025-21159HIGH7.8Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitr...
CVE-2025-21156HIGH7.8InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that co...
CVE-2025-24472HIGH8.1An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0....
CVE-2025-24470HIGH8.6An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2....
CVE-2025-22399HIGH7.8Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attack...
CVE-2025-21158HIGH7.8InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnera...
CVE-2025-21157HIGH7.8InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could r...
CVE-2025-21123HIGH7.8InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2025-21121HIGH7.8InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could r...
CVE-2025-24900HIGH8.6Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF coun...
CVE-2025-24897HIGH8.2Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-a...
CVE-2025-24896HIGH8.1Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-a...
CVE-2025-24807HIGH7.1eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ...
CVE-2025-22467HIGH8.8A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to...
CVE-2025-24812HIGH7.1A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), S...
CVE-2025-24811HIGH8.7A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 121...
CVE-2025-24499HIGH7.5A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1...
CVE-2025-23403HIGH7.3A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The ...
CVE-2025-23363HIGH7.4A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14....
CVE-2025-26411HIGH8.8An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to uplo...
CVE-2025-0525HIGH7.5In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a targ...
CVE-2025-1179HIGH7.5A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now