2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-44643HIGH8.6Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R...
CVE-2025-36594CRITICAL9.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-30099HIGH7.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-30098MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-30097MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-30096MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-26065HIGH7.3A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb...
CVE-2025-8109HIGH8.8Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read o...
CVE-2025-36607HIGH7.8Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authen...
CVE-2025-36606HIGH7.8Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An...
CVE-2025-36605MEDIUM6.1Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-...
CVE-2025-36604CRITICAL9.8Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-8515LOW3.7A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1...
CVE-2025-6205CRITICAL9.1A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an atta...
CVE-2025-6204HIGH8An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu...
CVE-2025-0932MEDIUM4.3Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm ...
CVE-2025-8341MEDIUM5Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafa...
CVE-2025-41691HIGH7.5An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime system...
CVE-2025-41659HIGH8.3A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri...
CVE-2025-41658MEDIUM5.5CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to ...
CVE-2025-20702HIGH8.8In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remo...
CVE-2025-20701HIGH8.8In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou...
CVE-2025-20700HIGH8.8In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc...
CVE-2025-48499MEDIUM6.9Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printin...
CVE-2025-54962MEDIUM6.4/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now