2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47553HIGH8.8Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is...
CVE-2025-36589HIGH7.1Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul...
CVE-2025-59379HIGH7.5DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information f...
CVE-2025-14979HIGH7.8AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege...
CVE-2025-14026HIGH7.8Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5...
CVE-2025-14997HIGH8.8The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic...
CVE-2025-12793HIGH7.8An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap...
CVE-2025-20801HIGH7In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile...
CVE-2025-20800HIGH7.8In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20799HIGH7.8In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i...
CVE-2025-20798HIGH7.8In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20797HIGH7.8In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20796HIGH7.8In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation...
CVE-2025-20795HIGH7.8In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio...
CVE-2025-20781HIGH7.8In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20780HIGH7.8In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20779HIGH7In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege...
CVE-2025-20778HIGH7.8In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-15364HIGH7.3The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up ...
CVE-2025-69228HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques...
CVE-2025-69227HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an i...
CVE-2025-69223HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo...
CVE-2025-68953HIGH7.5Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests...
CVE-2025-68455HIGH7.2Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar...
CVE-2025-68454HIGH8.8Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now