2025 CVE Vulnerabilities

45,245 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54241MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54240MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54239MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54084HIGH8.5OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated a...
CVE-2025-54083MEDIUM5.1Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin acc...
CVE-2025-44595MEDIUM6.1Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
CVE-2025-44593MEDIUM6.1Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. S...
CVE-2025-43491CRITICAL9.8A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi...
CVE-2025-34178MEDIUM5.4In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-relate...
CVE-2025-34177MEDIUM5.4In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-relate...
CVE-2025-34176MEDIUM4.3In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory trav...
CVE-2025-23344CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privi...
CVE-2025-23343CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A succ...
CVE-2025-23342CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A succ...
CVE-2025-10170HIGH8.8A security vulnerability has been detected in UTT 1200GW up to 3.0.0-170831. This affects the function sub_4B48F8 of the...
CVE-2025-10169HIGH8.8A weakness has been identified in UTT 1200GW up to 3.0.0-170831. Affected by this issue is some unknown functionality of...
CVE-2025-10159CRITICAL9.8An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi...
CVE-2025-7635HIGH7.7Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT...
CVE-2025-58762HIGH7.2Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attac...
CVE-2025-58761HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Ta...
CVE-2025-58760HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2....
CVE-2025-58759MEDIUM6.5TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly s...
CVE-2025-58758HIGH7.3TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did...
CVE-2025-58753HIGH7.5Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares fea...
CVE-2025-58442MEDIUM5.3Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now