2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-37178HIGH7.5Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ...
CVE-2025-37176HIGH7.2A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject s...
CVE-2025-37175HIGH7.2Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either A...
CVE-2025-37174HIGH7.2Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors run...
CVE-2025-37173HIGH7.2An improper input handling vulnerability exists in the web-based management interface of mobility conductors running eit...
CVE-2025-37172HIGH7.2Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni...
CVE-2025-37171HIGH7.2Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni...
CVE-2025-37170HIGH7.2Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni...
CVE-2025-37169HIGH7.2A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exp...
CVE-2025-37166HIGH7.5A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specia...
CVE-2025-37165HIGH7.5A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration d...
CVE-2025-10865HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of refe...
CVE-2025-68707HIGH8.8An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne...
CVE-2025-59922HIGH7.2An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi...
CVE-2025-58411HIGH8.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso...
CVE-2025-46685HIGH7.8Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio...
CVE-2025-25652HIGH7.5In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vul...
CVE-2025-71101HIGH7.1In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix out-of-bounds array a...
CVE-2025-71100HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9...
CVE-2025-71099HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_io...
CVE-2025-71093HIGH7.1In the Linux kernel, the following vulnerability has been resolved: e1000: fix OOB in e1000_tbi_should_accept() In e10...
CVE-2025-71092HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_sta...
CVE-2025-71091HIGH7.8In the Linux kernel, the following vulnerability has been resolved: team: fix check for port enabled in team_queue_over...
CVE-2025-71089HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch se...
CVE-2025-71086HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now