2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66620HIGH7.2An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An...
CVE-2025-64305HIGH7.1MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend...
CVE-2025-66560HIGH7.5Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3....
CVE-2025-4677HIGH7.1Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi...
CVE-2025-67366HIGH7.5@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil...
CVE-2025-67364HIGH7.5fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including...
CVE-2025-66786HIGH7.5OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att...
CVE-2025-65805HIGH7.5OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at...
CVE-2025-4676HIGH8.8Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-4675HIGH7.1Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-46494HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove Widget...
CVE-2025-9611HIGH7.2Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. Th...
CVE-2025-69082HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo ...
CVE-2025-69081HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69080HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47396HIGH7.8Memory corruption occurs when a secure application is launched on a device with insufficient memory.
CVE-2025-47394HIGH7.8Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
CVE-2025-47393HIGH7.8Memory corruption when accessing resources in kernel driver.
CVE-2025-47388HIGH7.8Memory corruption while passing pages to DSP with an unaligned starting address.
CVE-2025-47380HIGH7.8Memory corruption while preprocessing IOCTLs in sensors.
CVE-2025-47356HIGH7.8Memory Corruption when multiple threads concurrently access and modify shared resources.
CVE-2025-47348HIGH7.8Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346HIGH7.8Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345HIGH8.4Cryptographic issue may occur while encrypting license data.
CVE-2025-47343HIGH7.8Memory corruption while processing a video session to set video parameters.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now