2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68800HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_mr: Fix use-after-free when updatin...
CVE-2025-68799HIGH8.1In the Linux kernel, the following vulnerability has been resolved: caif: fix integer underflow in cffrml_receive() Th...
CVE-2025-68795HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ethtool: Avoid overflowing userspace buffer on stat...
CVE-2025-68793HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix a job->pasid access race in gpu rec...
CVE-2025-68792HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tpm2-sessions: Fix out of range indexing in name_si...
CVE-2025-68785HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix middle attribute validation i...
CVE-2025-68782HIGH7.5In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error cas...
CVE-2025-68774HIGH7.5In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix missing hfs_bnode_get() in __hfs_bnode...
CVE-2025-68770HIGH7.5In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix XDP_TX path For XDP_TX action in bnxt...
CVE-2025-66698HIGH8.6An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to var...
CVE-2025-36640HIGH8.8A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts whi...
CVE-2025-9427HIGH8.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft W...
CVE-2025-11669HIGH8.1Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versi...
CVE-2025-13774HIGH8.8A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability ...
CVE-2025-59022HIGH8.1Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the T...
CVE-2025-40944HIGH8.7A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200M...
CVE-2025-40942HIGH7.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains...
CVE-2025-41717HIGH8.8An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-up...
CVE-2025-66177HIGH8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models....
CVE-2025-66176HIGH8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products...
CVE-2025-15514HIGH7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal mod...
CVE-2025-46068HIGH8.8An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
CVE-2025-46067HIGH8.2An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information v...
CVE-2025-71063HIGH7.5Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.
CVE-2025-41078HIGH8.1Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now