2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66224HIGH8.8OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains a...
CVE-2025-66223HIGH8.4OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not exp...
CVE-2025-66217HIGH7.5AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQ...
CVE-2025-53939HIGH8.8Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a sh...
CVE-2025-53900HIGH8.8Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of rol...
CVE-2025-53899HIGH7.2Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is ...
CVE-2025-53896HIGH8.1Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus...
CVE-2025-66201HIGH8.1LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-sid...
CVE-2025-12183HIGH8.8Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service ...
CVE-2025-51735HIGH7.5CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-12638HIGH8Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin...
CVE-2025-13771HIGH7.1WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit ...
CVE-2025-13770HIGH7.1WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2025-13769HIGH7.1WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2025-13768HIGH8.8WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in...
CVE-2025-66384HIGH8.2app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela...
CVE-2025-64312HIGH7.5Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma...
CVE-2025-58311HIGH7.1UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availabili...
CVE-2025-64315HIGH7.1Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-58314HIGH7.1Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner...
CVE-2025-58309HIGH7.1Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w...
CVE-2025-66360HIGH8.8An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo...
CVE-2025-13757HIGH8.8SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025...
CVE-2025-13692HIGH7.2The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2025-59890HIGH7.3Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now