2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66292HIGH8.1DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vu...
CVE-2025-67246HIGH7.3A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control ...
CVE-2025-67077HIGH8.8File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions al...
CVE-2025-67076HIGH7.5Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read fil...
CVE-2025-64516HIGH7.5GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GL...
CVE-2025-61973HIGH8.8A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A...
CVE-2025-71019HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. T...
CVE-2025-70744HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. ...
CVE-2025-13062HIGH8.8The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin...
CVE-2025-14457HIGH7.4The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2025-13455HIGH7.8A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T...
CVE-2025-12166HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli...
CVE-2025-33206HIGH7.8NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful ...
CVE-2025-71021HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function....
CVE-2025-70747HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function...
CVE-2025-37183HIGH7.2Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2025-37182HIGH7.2Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2025-37181HIGH7.2Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2025-9142HIGH7.5A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working d...
CVE-2025-71143HIGH7.8In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before acc...
CVE-2025-71137HIGH7.8In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix "UBSAN: shift-out-of-bounds error...
CVE-2025-71136HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: adv7842: Avoid possible out-of-bounds array ...
CVE-2025-71133HIGH7.1In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: avoid invalid read in irdma_net_event ...
CVE-2025-71123HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_op...
CVE-2025-71122HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now