2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54276HIGH7.8Substance3D - Modeler versions 1.22.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra...
CVE-2025-34267CRITICAL9.9Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec...
CVE-2025-33177MEDIUM5.5NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all...
CVE-2025-54280HIGH7.8Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54275MEDIUM5.5Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to...
CVE-2025-54274HIGH7.8Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could ...
CVE-2025-54273HIGH7.8Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-33182HIGH7.6NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause...
CVE-2025-8459MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-60537MEDIUM6.5Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a...
CVE-2025-60536HIGH7.5An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Servi...
CVE-2025-57618HIGH7.3A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the s...
CVE-2025-57563MEDIUM6.5A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to rea...
CVE-2025-23356HIGH8.4NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might...
CVE-2025-11736CRITICAL9.8A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit...
CVE-2025-8430MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-60535HIGH7.3A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to e...
CVE-2025-59502HIGH7.5Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over ...
CVE-2025-59497MEDIUM4.7Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny ...
CVE-2025-59494HIGH7.8Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-59295HIGH8.8Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
CVE-2025-59294MEDIUM4.6Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di...
CVE-2025-59292HIGH8.2External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate...
CVE-2025-59291HIGH8.2External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate...
CVE-2025-59290HIGH7.8Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now