2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48478MEDIUM4.9FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation du...
CVE-2025-48477HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires...
CVE-2025-48476HIGH8.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user rec...
CVE-2025-48491LOW2.7Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in...
CVE-2025-48381MEDIUM4.3Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In version...
CVE-2025-48068MEDIUM4.3Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 ...
CVE-2025-47952CRITICAL9.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a...
CVE-2025-44906HIGH7.8jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
CVE-2025-44905HIGH8.8hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.
CVE-2025-44904HIGH8.8hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
CVE-2025-48757CRITICAL9.3An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers...
CVE-2025-44619CRITICAL9.1Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attacker...
CVE-2025-44614HIGH7.5Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile ...
CVE-2025-44612MEDIUM5.9Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control inform...
CVE-2025-46352CRITICAL9.8The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string i...
CVE-2025-41438CRITICAL9.8The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to ch...
CVE-2025-1907CRITICAL9.8Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if co...
CVE-2025-5332CRITICAL9.8A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some u...
CVE-2025-5331CRITICAL9.8A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown ...
CVE-2025-5330CRITICAL9.8A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o...
CVE-2025-5307HIGH7.8Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue t...
CVE-2025-31264MEDIUM4.6An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS S...
CVE-2025-31263CRITICAL9.1The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to ...
CVE-2025-31261MEDIUM5.5A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS...
CVE-2025-31231MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now