2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0083MEDIUM4In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This c...
CVE-2025-0082MEDIUM5.5In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across us...
CVE-2025-0081HIGH7.5In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitiali...
CVE-2025-0080HIGH7.8In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overl...
CVE-2025-0079HIGH7.8In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error i...
CVE-2025-0078HIGH8.8In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to loca...
CVE-2025-0075CRITICAL9.8In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use afte...
CVE-2025-0074CRITICAL9.8In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after fr...
CVE-2025-9492CRITICAL9.8A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the fil...
CVE-2025-55443CRITICAL9.1Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (...
CVE-2025-52353CRITICAL9.8An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload f...
CVE-2025-50971HIGH7.5Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensiti...
CVE-2025-9478HIGH8.8Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap c...
CVE-2025-50975MEDIUM5.4IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT...
CVE-2025-23315HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious dat...
CVE-2025-23314HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a...
CVE-2025-23313HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a...
CVE-2025-23312HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious da...
CVE-2025-23307HIGH7.8NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow...
CVE-2025-57818MEDIUM6.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side reques...
CVE-2025-57803HIGH8.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-55298HIGH8.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick vers...
CVE-2025-50976MEDIUM6.1IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK,...
CVE-2025-9491HIGH7.8Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2025-57425MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated at...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now