2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6386HIGH7.5The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within t...
CVE-2025-6210MEDIUM6.2A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, al...
CVE-2025-5472MEDIUM6.5The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive...
CVE-2025-4779MEDIUM6.1lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attack...
CVE-2025-3777LOW3.5Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image...
CVE-2025-3705MEDIUM6.8A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp...
CVE-2025-3626CRITICAL9.1A remote attacker with administrator account can gain full control of the device due to improper neutralization of speci...
CVE-2025-3467MEDIUM5.4An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vu...
CVE-2025-3466HIGH7.2langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbi...
CVE-2025-3264MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-3263MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-3262HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, ...
CVE-2025-3225HIGH7.5An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-...
CVE-2025-3046HIGH7.5A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allo...
CVE-2025-3044MEDIUM5.3A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows ...
CVE-2025-7121HIGH8.8A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects...
CVE-2025-7120CRITICAL9.8A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issu...
CVE-2025-3920HIGH8.5A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These...
CVE-2025-7119CRITICAL9.8A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this...
CVE-2025-7118HIGH8.8A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affec...
CVE-2025-7117HIGH8.8A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknow...
CVE-2025-7116HIGH7.5A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of...
CVE-2025-41672CRITICAL10A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool a...
CVE-2025-7115HIGH7.3A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr...
CVE-2025-7114HIGH7.5A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now