2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6633HIGH7.8A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2025-6632HIGH7.8A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-51058MEDIUM6.5Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/pr...
CVE-2025-51057MEDIUM6.5A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read a...
CVE-2025-51056HIGH8.2An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t...
CVE-2025-51055HIGH8.6Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202...
CVE-2025-51054MEDIUM6.5Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privi...
CVE-2025-51053MEDIUM6.1A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject...
CVE-2025-51052MEDIUM6.5A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem ...
CVE-2025-50740MEDIUM6.1AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web ...
CVE-2025-47908HIGH7.5Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A...
CVE-2025-46660MEDIUM5.3An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.
CVE-2025-51624HIGH7.6Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.
CVE-2025-46659HIGH7.5An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT...
CVE-2025-45766HIGH7poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key...
CVE-2025-45764LOW3.2jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who bel...
CVE-2025-38747HIGH7.8Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio...
CVE-2025-38746LOW2.4Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthor...
CVE-2025-8130Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-8667MEDIUM6.3A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75b...
CVE-2025-8665MEDIUM6.3A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the f...
CVE-2025-8419MEDIUM5.3A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Inje...
CVE-2025-30127CRITICAL9.8An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or c...
CVE-2025-20332MEDIUM4.3A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modi...
CVE-2025-20331MEDIUM5.4A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now