2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68111HIGH7.2ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i...
CVE-2025-68110HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er...
CVE-2025-68109HIGH7.2ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe...
CVE-2025-67877HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the ...
CVE-2025-67873HIGH7.8Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a use...
CVE-2025-67792HIGH7.8An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ...
CVE-2025-67790HIGH7.5An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use...
CVE-2025-53000HIGH7.8The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions...
CVE-2025-46291HIGH7.8A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An ...
CVE-2025-46281HIGH8.8A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macO...
CVE-2025-43529HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and...
CVE-2025-66646HIGH7.5RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2025-66397HIGH8.3ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload...
CVE-2025-66396HIGH7.2ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-34442HIGH7.5AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in...
CVE-2025-34441HIGH7.5AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response...
CVE-2025-34438HIGH8.1AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi...
CVE-2025-34437HIGH8.8AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The...
CVE-2025-34436HIGH8.8AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due...
CVE-2025-67174HIGH7.5A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ...
CVE-2025-67171HIGH7.5Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d...
CVE-2025-66953HIGH8.8CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co...
CVE-2025-66395HIGH8.8ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-67172HIGH7.2RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia...
CVE-2025-66923HIGH7.2A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now