2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24886HIGH7.7pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. In...
CVE-2025-24885HIGH7.6pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Mi...
CVE-2025-0882HIGH7.5A vulnerability was found in code-projects Chat System up to 1.0. It has been declared as critical. Affected by this vul...
CVE-2025-0574HIGH7.5Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers...
CVE-2025-0569HIGH7.5Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote a...
CVE-2025-0568HIGH7.5Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote a...
CVE-2025-24802HIGH8.6Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible b...
CVE-2025-0145HIGH7.8Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct ...
CVE-2025-24507HIGH8.9This vulnerability allows appliance compromise at boot time.
CVE-2025-24505HIGH8.8This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected P...
CVE-2025-24500HIGH8.7The vulnerability allows an unauthenticated attacker to access information in PAM database.
CVE-2025-0683HIGH8.2In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded p...
CVE-2025-0626HIGH7.7The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, byp...
CVE-2025-24883HIGH8.7go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced ...
CVE-2025-22218HIGH7.7VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin...
CVE-2025-21107HIGH7.8Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path...
CVE-2025-0861HIGH7.2The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all...
CVE-2025-0834HIGH7.8Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow...
CVE-2025-0849HIGH8.1A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknow...
CVE-2025-21415HIGH8.8Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a ne...
CVE-2025-21396HIGH8.2Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-24794HIGH7.8The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak...
CVE-2025-24793HIGH7The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak...
CVE-2025-0841HIGH7.3A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability ...
CVE-2025-0840HIGH7.5A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function di...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now