2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43962CRITICAL9.1In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing...
CVE-2025-43961CRITICAL9.1In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
CVE-2025-43955MEDIUM6.8TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expr...
CVE-2025-43954MEDIUM6.1QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.
CVE-2025-3830CRITICAL9.8A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerabi...
CVE-2025-3829CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is...
CVE-2025-3828CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s...
CVE-2025-3827CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil...
CVE-2025-3826MEDIUM4.1A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management ...
CVE-2025-3825MEDIUM4.1A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Manage...
CVE-2025-3824MEDIUM4.1A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. ...
CVE-2025-3823MEDIUM4.1A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System ...
CVE-2025-3822MEDIUM5.4A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as probl...
CVE-2025-3821MEDIUM5.4A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as pr...
CVE-2025-43929HIGH7.8open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that ma...
CVE-2025-43928CRITICAL9.8In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../...
CVE-2025-43921MEDIUM5.3GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/cr...
CVE-2025-43920HIGH8.1GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated ...
CVE-2025-43919HIGH7.5GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ dir...
CVE-2025-43918MEDIUM6.4SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a ...
CVE-2025-3820HIGH8.8A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this ...
CVE-2025-3819CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-3818MEDIUM6.3A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._...
CVE-2025-43917HIGH8.2In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst...
CVE-2025-3817HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now