2025 CVE Vulnerabilities

45,294 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46726CRITICAL9.1Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM applicati...
CVE-2025-45618MEDIUM6.5Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE all...
CVE-2025-45617HIGH7.5Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensit...
CVE-2025-45616CRITICAL9.8Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a craft...
CVE-2025-45615CRITICAL9.8Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights...
CVE-2025-45614HIGH7.5Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information...
CVE-2025-45613HIGH7.5Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati...
CVE-2025-45612CRITICAL9.8Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
CVE-2025-45611CRITICAL9.8Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via ...
CVE-2025-45610HIGH7.5Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen...
CVE-2025-45609HIGH7.5Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf...
CVE-2025-45608HIGH7.5Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens...
CVE-2025-45607CRITICAL9.8An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.
CVE-2025-1909CRITICAL9.8The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,...
CVE-2025-4318CRITICAL9The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input valida...
CVE-2025-4283CRITICAL9.8A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue...
CVE-2025-4279HIGH8.8The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-46720MEDIUM4.3Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can b...
CVE-2025-46719MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6....
CVE-2025-46571MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6....
CVE-2025-46559HIGH7.5Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m...
CVE-2025-46553MEDIUM6.1@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1...
CVE-2025-46340MEDIUM5.4Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, du...
CVE-2025-46335MEDIUM5.4Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo...
CVE-2025-43852CRITICAL9.8Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now