2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68662CRITICAL9.9Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn...
CVE-2025-68119HIGH7Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria...
CVE-2025-61731HIGH7.8Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of...
CVE-2025-61730MEDIUM5.3During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc...
CVE-2025-61728MEDIUM6.5archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open...
CVE-2025-61726HIGH7.5The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p...
CVE-2025-46691HIGH7.8Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low ...
CVE-2025-14840HIGH7.5Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsin...
CVE-2025-14472HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issu...
CVE-2025-13986MEDIUM4.2Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality...
CVE-2025-13985MEDIUM5.3Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: f...
CVE-2025-13984MEDIUM6.1Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripti...
CVE-2025-13983MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo...
CVE-2025-13982HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This ...
CVE-2025-13981MEDIUM4.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artific...
CVE-2025-13980MEDIUM5.3Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Func...
CVE-2025-13979MEDIUM5.4Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: ...
CVE-2025-71001MEDIUM6.5A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Serv...
CVE-2025-69602CRITICAL9.1A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th...
CVE-2025-69601MEDIUM6.5A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. ...
CVE-2025-68660MEDIUM5.4Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endp...
CVE-2025-68659MEDIUM5.3Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an app...
CVE-2025-68479MEDIUM5.3Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su...
CVE-2025-67723MEDIUM5.4Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont...
CVE-2025-66488MEDIUM6.1Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now