2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71394MEDIUM4.3SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut...
CVE-2025-71393MEDIUM6.5SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e...
CVE-2025-71392HIGH8SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the...
CVE-2025-71391MEDIUM6.5SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ...
CVE-2025-71390HIGH8.8SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains...
CVE-2025-51678HIGH7.5An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une...
CVE-2025-51677CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12...
CVE-2025-59866LOW3.3The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es...
CVE-2025-60357HIGH8.1AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv...
CVE-2025-45870MEDIUM6.5LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c...
CVE-2025-45868HIGH8.8LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo...
CVE-2025-71388HIGH7.6stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ...
CVE-2025-71377HIGH8.7stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me...
CVE-2025-65720CRITICAL9.8An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user...
CVE-2025-32781MEDIUM6.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior...
CVE-2025-56365HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co...
CVE-2025-56364HIGH7.5A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin...
CVE-2025-56363HIGH7.5A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi...
CVE-2025-56362HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev...
CVE-2025-56361HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev...
CVE-2025-62826MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-62675MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-53379HIGH7.5A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio...
CVE-2025-43892MEDIUM4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v...
CVE-2025-11698CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now