2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68459HIGH7.2RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injec...
CVE-2025-47387HIGH7.8Memory Corruption when processing IOCTLs for JPEG data without verification.
CVE-2025-47382HIGH7.8Memory corruption while loading an invalid firmware in boot loader.
CVE-2025-47372HIGH8.4Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
CVE-2025-47350HIGH7.8Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
CVE-2025-47323HIGH7.8Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-47322HIGH7.8Memory corruption while handling IOCTL calls to set mode.
CVE-2025-47321HIGH7.8Memory corruption while copying packets received from unix clients.
CVE-2025-47320HIGH7.8Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27063HIGH7.8Memory corruption during video playback when video session open fails with time out error.
CVE-2025-68460HIGH7.5Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML sty...
CVE-2025-14856HIGH8.8A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function o...
CVE-2025-14837HIGH7.2A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/sitecon...
CVE-2025-14202HIGH8.2A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG f...
CVE-2025-68434HIGH8.8Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68433HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo...
CVE-2025-68432HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La...
CVE-2025-68147HIGH8.1Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68144HIGH7.1In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments...
CVE-2025-68143HIGH8.8Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp...
CVE-2025-66029HIGH7.6Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti...
CVE-2025-14834HIGH8.8A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /c...
CVE-2025-68400HIGH8.8ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo...
CVE-2025-68129HIGH7.5Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the a...
CVE-2025-68112HIGH8.8ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in Churc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now