2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13151HIGH7.5Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resultin...
CVE-2025-66620HIGH7.2An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An...
CVE-2025-64305HIGH7.1MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend...
CVE-2025-66560HIGH7.5Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3....
CVE-2025-4677HIGH7.1Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi...
CVE-2025-67366HIGH7.5@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil...
CVE-2025-67364HIGH7.5fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including...
CVE-2025-66786HIGH7.5OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att...
CVE-2025-65805HIGH7.5OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at...
CVE-2025-4676HIGH8.8Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-4675HIGH7.1Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-46494HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove Widget...
CVE-2025-9611HIGH7.2Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. Th...
CVE-2025-69082HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo ...
CVE-2025-69081HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69080HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47396HIGH7.8Memory corruption occurs when a secure application is launched on a device with insufficient memory.
CVE-2025-47394HIGH7.8Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
CVE-2025-47393HIGH7.8Memory corruption when accessing resources in kernel driver.
CVE-2025-47388HIGH7.8Memory corruption while passing pages to DSP with an unaligned starting address.
CVE-2025-47380HIGH7.8Memory corruption while preprocessing IOCTLs in sensors.
CVE-2025-47356HIGH7.8Memory Corruption when multiple threads concurrently access and modify shared resources.
CVE-2025-47348HIGH7.8Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346HIGH7.8Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345HIGH8.4Cryptographic issue may occur while encrypting license data.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now