2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-15107HIGH8.1A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio...
CVE-2025-68948HIGH8.1SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note ...
CVE-2025-59946HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss...
CVE-2025-68474HIGH7.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ...
CVE-2025-68473HIGH8.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ...
CVE-2025-68148HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny ...
CVE-2025-67729HIGH8.8LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization...
CVE-2025-67015HIGH7.5Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows atta...
CVE-2025-67014HIGH7.5Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauth...
CVE-2025-66738HIGH8.8An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a ...
CVE-2025-57403HIGH7.5Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application...
CVE-2025-64645HIGH7.4IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbo...
CVE-2025-25341HIGH7.5A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref...
CVE-2025-36192HIGH7.1IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089....
CVE-2025-1721HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-12771HIGH7.8IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A lo...
CVE-2025-67450HIGH7.8Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software ...
CVE-2025-59887HIGH8.6Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec...
CVE-2025-62578HIGH7.5DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
CVE-2025-52601HIGH7.8Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-52600HIGH7.2Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-15097HIGH7.3A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/a...
CVE-2025-15085HIGH8.1A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th...
CVE-2025-15082HIGH7.5A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post o...
CVE-2025-2406HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now