2025 CVE Vulnerabilities

45,245 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10172HIGH8.8A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/for...
CVE-2025-9997MEDIUM5.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-59036MEDIUM5.5Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the ...
CVE-2025-58135MEDIUM6.5Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a...
CVE-2025-58134MEDIUM4.3Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impa...
CVE-2025-58131MEDIUM6.6Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or b...
CVE-2025-54260HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra...
CVE-2025-54259HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that c...
CVE-2025-54258HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in ar...
CVE-2025-49461HIGH7.4Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service ...
CVE-2025-49460HIGH7.5Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denia...
CVE-2025-49459HIGH7.8Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authentic...
CVE-2025-49458MEDIUM6.5Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via net...
CVE-2025-10171HIGH8.8A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the ...
CVE-2025-9996MEDIUM5.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-7746MEDIUM5.3CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c...
CVE-2025-59037HIGH8.6DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Nod...
CVE-2025-58768CRITICAL9.6DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo...
CVE-2025-58765HIGH7.1wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site ...
CVE-2025-58763HIGH7.2Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Taut...
CVE-2025-58462CRITICAL9.8OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r...
CVE-2025-57633CRITICAL9.8A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute...
CVE-2025-54245HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54244HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r...
CVE-2025-54243HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now