2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58479HIGH7.5Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bo...
CVE-2025-58478HIGH7.5Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-b...
CVE-2025-21080HIGH7.1Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local att...
CVE-2025-66448HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote co...
CVE-2025-66313HIGH7.2ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL in...
CVE-2025-66304HIGH7.2Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section...
CVE-2025-66300HIGH8.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can ...
CVE-2025-66299HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S...
CVE-2025-66298HIGH7.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav config...
CVE-2025-66297HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or e...
CVE-2025-66296HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin p...
CVE-2025-66295HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new use...
CVE-2025-66294HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists ...
CVE-2025-66206HIGH8.6Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path...
CVE-2025-65840HIGH8.8PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
CVE-2025-55749HIGH7.5XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is usin...
CVE-2025-65838HIGH7.5PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
CVE-2025-63365HIGH7.1SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file proces...
CVE-2025-34297HIGH8.6KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platf...
CVE-2025-13836HIGH7.5When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content...
CVE-2025-7007HIGH7.5NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed W...
CVE-2025-8351HIGH7.8Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file ma...
CVE-2025-64775HIGH7.5Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi...
CVE-2025-63535HIGH8.8A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The applicati...
CVE-2025-63532HIGH8.8A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The applic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now