2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68433HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo...
CVE-2025-68432HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La...
CVE-2025-68147HIGH8.1Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68144HIGH7.1In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments...
CVE-2025-68143HIGH8.8Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp...
CVE-2025-66029HIGH7.6Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti...
CVE-2025-14834HIGH8.8A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /c...
CVE-2025-68400HIGH8.8ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo...
CVE-2025-68129HIGH7.5Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the a...
CVE-2025-68112HIGH8.8ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in Churc...
CVE-2025-68111HIGH7.2ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i...
CVE-2025-68110HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er...
CVE-2025-68109HIGH7.2ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe...
CVE-2025-67877HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the ...
CVE-2025-67873HIGH7.8Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a use...
CVE-2025-67792HIGH7.8An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ...
CVE-2025-67790HIGH7.5An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use...
CVE-2025-53000HIGH7.8The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions...
CVE-2025-46291HIGH7.8A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekee...
CVE-2025-46281HIGH8.8A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2. An app may be able to break o...
CVE-2025-43529HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and...
CVE-2025-66646HIGH7.5RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2025-66397HIGH8.3ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload...
CVE-2025-66396HIGH7.2ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-34442HIGH7.5AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now