2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54365HIGH7.5fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetratio...
CVE-2025-54377HIGH7.8Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode d...
CVE-2025-54371Rejected reason: This CVE is a duplicate of another CVE.
CVE-2025-53942HIGH7.4authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set o...
CVE-2025-53537HIGH7.5LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, t...
CVE-2025-47281HIGH7.7Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial ...
CVE-2025-32019MEDIUM4.1Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 an...
CVE-2025-8058MEDIUM5.9The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocat...
CVE-2025-44109MEDIUM5.4A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.
CVE-2025-50477MEDIUM5.4A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.
CVE-2025-47187HIGH7.5A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th...
CVE-2025-46686LOW3.5Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated ...
CVE-2025-4700MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18...
CVE-2025-4439MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18...
CVE-2025-8069HIGH7.8During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\window...
CVE-2025-50481MEDIUM4.8A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers ...
CVE-2025-46171MEDIUM5.4vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticat...
CVE-2025-2634HIGH7.8Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in fontmgr may result in information disc...
CVE-2025-2633HIGH7.8Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in lvre!UDecStrToNum that may result in i...
CVE-2025-6018HIGH7.8A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication...
CVE-2025-40598MEDIUM6.1A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauth...
CVE-2025-40597HIGH7.5A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to...
CVE-2025-40596HIGH7.3A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker t...
CVE-2025-36117MEDIUM6.3IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated use...
CVE-2025-36116MEDIUM6.3IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a sp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now