2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5100HIGH8A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory cor...
CVE-2025-5099CRITICAL9.8An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c...
CVE-2025-5098CRITICAL9.1PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's...
CVE-2025-2394MEDIUM4.7Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alib...
CVE-2025-4692MEDIUM6.8Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation b...
CVE-2025-4642Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-4562Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-4338MEDIUM6.9Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the netwo...
CVE-2025-48371HIGH8.8OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfg...
CVE-2025-4975MEDIUM4.8When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notific...
CVE-2025-47181HIGH8.8Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a...
CVE-2025-48374MEDIUM5.5zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to v...
CVE-2025-48373CRITICAL9.1Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to ...
CVE-2025-48372HIGH7.3Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time...
CVE-2025-48369MEDIUM5.4Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20...
CVE-2025-48368MEDIUM5.4Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20...
CVE-2025-48366MEDIUM5.4Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20...
CVE-2025-48075HIGH7.5Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber...
CVE-2025-48066MEDIUM5.5wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an ...
CVE-2025-30173MEDIUM6.7File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue aff...
CVE-2025-30172HIGH8.9Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This...
CVE-2025-30171CRITICAL9System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator ...
CVE-2025-30170MEDIUM5.9Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system inf...
CVE-2025-30169MEDIUM6.7File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become...
CVE-2025-2410CRITICAL9.1Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now