2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-0413HIGH7.8Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability a...
CVE-2025-23023HIGH8.2Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a re...
CVE-2025-24968HIGH8.8reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability al...
CVE-2025-24964HIGH8.8Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when acc...
CVE-2025-24963HIGH7.5Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that res...
CVE-2025-25039HIGH8.8A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows rem...
CVE-2025-23060HIGH8.1A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unen...
CVE-2025-23058HIGH8.1A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authe...
CVE-2025-24648HIGH7.5Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Pr...
CVE-2025-24602HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain C...
CVE-2025-24599HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software...
CVE-2025-23645HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide...
CVE-2025-22794HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ianhaycox World Cu...
CVE-2025-22700HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-1014HIGH8.8Certificate length was not properly checked when added to a certificate store. In practice only trusted data was process...
CVE-2025-1012HIGH7.5A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135,...
CVE-2025-1011HIGH8.8A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage t...
CVE-2025-1010HIGH8.8An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash....
CVE-2025-23015HIGH8.8Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES...
CVE-2025-22205HIGH7.5Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension fo...
CVE-2025-20890HIGH7.8Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to e...
CVE-2025-20888HIGH7.8Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local ...
CVE-2025-20882HIGH7.8Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows ...
CVE-2025-20881HIGH7.8Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1...
CVE-2025-22475HIGH7.5Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primiti...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now