2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2405HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com...
CVE-2025-2307HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com...
CVE-2025-66379HIGH7.5Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trig...
CVE-2025-66378HIGH7.5Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacke...
CVE-2025-66377HIGH7.5Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an att...
CVE-2025-48704HIGH7.5Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trig...
CVE-2025-32096HIGH7.5Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigg...
CVE-2025-32095HIGH7.5Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a softwa...
CVE-2025-15076HIGH7.3A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a ...
CVE-2025-68922HIGH7.4OpenOps before 0.6.11 allows remote code execution in the Terraform block.
CVE-2025-68920HIGH8.9C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite f...
CVE-2025-68916HIGH7.2Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi...
CVE-2025-3232HIGH8.7A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arb...
CVE-2025-2515HIGH7.2A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user wi...
CVE-2025-43876HIGH8.7Under certain circumstances a successful exploitation could result in access to the device.
CVE-2025-43875HIGH8.7Under certain circumstances a successful exploitation could result in access to the device.
CVE-2025-2155HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Spect...
CVE-2025-68748HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF race between device unplug and...
CVE-2025-68747HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF on kernel BO VA nodes If the ...
CVE-2025-68746HIGH7.8In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Fix timeout handling When the ...
CVE-2025-68736HIGH8.8In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories ...
CVE-2025-68735HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Prevent potential UAF in group creatio...
CVE-2025-68608HIGH7.5Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-68590HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integrat...
CVE-2025-68570HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Cap...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now