2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49464MEDIUM6.5Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service ...
CVE-2025-49463MEDIUM6.5Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated u...
CVE-2025-49462LOW3.5Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosu...
CVE-2025-47813MEDIUM4.3loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a ...
CVE-2025-47812CRITICAL10In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o...
CVE-2025-47811MEDIUM6.6In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or S...
CVE-2025-27889HIGH8.8Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint...
CVE-2025-23048CRITICAL9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien...
CVE-2025-6395MEDIUM6.5A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
CVE-2025-53364MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3....
CVE-2025-46789MEDIUM6.5Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service ...
CVE-2025-46788CRITICAL9.1Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to cond...
CVE-2025-7408MEDIUM5.4A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerabi...
CVE-2025-7370Rejected reason: Upon investigtion upstream maintainers discovered this was not a real issue. See the references for mor...
CVE-2025-7365HIGH7.1A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account du...
CVE-2025-46835HIGH8.5Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository ...
CVE-2025-46334HIGH8.6Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of...
CVE-2025-44251HIGH7.5Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.
CVE-2025-36090MEDIUM5.3IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the applicati...
CVE-2025-27614HIGH8.6Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that wit...
CVE-2025-27613LOW3.6Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs git...
CVE-2025-7425HIGH7.8A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory m...
CVE-2025-7424HIGH7.5A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which ...
CVE-2025-7407HIGH8.8A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of...
CVE-2025-6211MEDIUM6.5A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now