2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69765HIGH7.5Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus...
CVE-2025-67840HIGH7.2Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil...
CVE-2025-63912HIGH7.5Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da...
CVE-2025-63911HIGH7.2Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti...
CVE-2025-63910HIGH7.2An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al...
CVE-2025-63909HIGH7.8Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4....
CVE-2025-15599MEDIUM6.1DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers...
CVE-2025-62817HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ...
CVE-2025-62816MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4...
CVE-2025-66680HIGH7.1An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele...
CVE-2025-66363HIGH7.5An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit...
CVE-2025-62815MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference ...
CVE-2025-62814HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ...
CVE-2025-70821CRITICAL9.8renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
CVE-2025-64736HIGH7.1An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma...
CVE-2025-57622CRITICAL9.8An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ...
CVE-2025-52365HIGH7.8A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ...
CVE-2025-59060MEDIUM5.3Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions ...
CVE-2025-59059CRITICAL9.8Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ...
CVE-2025-15598MEDIUM5.9A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend...
CVE-2025-15595HIGH7.8Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
CVE-2025-12345HIGH8.8A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the functio...
CVE-2025-47147MEDIUM5.7Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow ...
CVE-2025-48654HIGH7.8In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. ...
CVE-2025-48653HIGH7.8In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now