2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62514HIGH7.1Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3....
CVE-2025-13905HIGH7CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse s...
CVE-2025-7714CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive...
CVE-2025-7713MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Inte...
CVE-2025-71009MEDIUM6.2An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to c...
CVE-2025-71008MEDIUM6.2A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable componen...
CVE-2025-7014HIGH8.8Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect...
CVE-2025-7013CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo...
CVE-2025-7016CRITICAL9.8Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut...
CVE-2025-7015CRITICAL9.8Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi...
CVE-2025-14975HIGH8.1The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a...
CVE-2025-55704MEDIUM6.9Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to ...
CVE-2025-53869MEDIUM6.3Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man...
CVE-2025-15344HIGH8.8Tanium addressed a SQL injection vulnerability in Asset.
CVE-2025-71007HIGH7.5An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denia...
CVE-2025-71006MEDIUM6.5A floating point exception (FPE) in the oneflow.reshape component of OneFlow v0.9.0 allows attackers to cause a Denial o...
CVE-2025-71005MEDIUM6.5A floating point exception (FPE) in the oneflow.view component of OneFlow v0.9.0 allows attackers to cause a Denial of S...
CVE-2025-71004MEDIUM6.5A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Ser...
CVE-2025-71003HIGH7.5An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of...
CVE-2025-71002MEDIUM6.5A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial...
CVE-2025-69289MEDIUM5.4Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.1...
CVE-2025-69218MEDIUM6.5Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderat...
CVE-2025-68934MEDIUM6.5Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authent...
CVE-2025-68933MEDIUM5.4Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm...
CVE-2025-68666MEDIUM6.5Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now