2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12744HIGH8.8A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from a...
CVE-2025-13645HIGH7.2The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2025-66476HIGH7.8Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on...
CVE-2025-64778HIGH7.8NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. The...
CVE-2025-64642HIGH7.8NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which...
CVE-2025-64298HIGH7.5NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose...
CVE-2025-62575HIGH8.8NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o...
CVE-2025-61940HIGH8.8NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User ...
CVE-2025-65877HIGH7.5Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 't...
CVE-2025-66416HIGH8.1The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi...
CVE-2025-66414HIGH8.1MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The M...
CVE-2025-61729HIGH7.5Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p...
CVE-2025-34352HIGH8.5JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Wi...
CVE-2025-13721HIGH7.5Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via ...
CVE-2025-13720HIGH8.8Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr...
CVE-2025-13639HIGH8.1Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi...
CVE-2025-13638HIGH8.8Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit ...
CVE-2025-13633HIGH8.8Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi...
CVE-2025-13631HIGH8.8Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker ...
CVE-2025-13630HIGH8.8Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-66399HIGH8.8Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i...
CVE-2025-65844HIGH7.5EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/im...
CVE-2025-13827HIGH8.8Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not res...
CVE-2025-64460HIGH7.5An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django...
CVE-2025-59702HIGH7.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now