2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5918MEDIUM6.6A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped in...
CVE-2025-5917MEDIUM5A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when ha...
CVE-2025-5916MEDIUM5.6A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be trigge...
CVE-2025-5915MEDIUM6.6A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the ...
CVE-2025-5914HIGH7.8A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data...
CVE-2025-5895HIGH7.5A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataU...
CVE-2025-5892HIGH7.5A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the f...
CVE-2025-5891MEDIUM5.3A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code ...
CVE-2025-5890MEDIUM5.3A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape ...
CVE-2025-5889LOW3.1A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problemat...
CVE-2025-5888MEDIUM6.5A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerabili...
CVE-2025-49653HIGH8Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users o...
CVE-2025-49652CRITICAL9.8Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts ...
CVE-2025-49651HIGH8.1Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or al...
CVE-2025-5887MEDIUM5.4A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown fun...
CVE-2025-49136MEDIUM6.5listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to versi...
CVE-2025-46041MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript ...
CVE-2025-45002MEDIUM5.4Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my pro...
CVE-2025-45001HIGH7.5react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chun...
CVE-2025-29627MEDIUM6.8An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Bio...
CVE-2025-5886MEDIUM4.1A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing...
CVE-2025-49297CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.T...
CVE-2025-49296CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issu...
CVE-2025-49295CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This is...
CVE-2025-49282HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now