2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10855HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows E...
CVE-2025-67684HIGH7.2Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart ...
CVE-2025-67683MEDIUM6.1Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when ope...
CVE-2025-10024HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Educatio...
CVE-2025-4764HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Info...
CVE-2025-4763MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Comput...
CVE-2025-13335MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 1...
CVE-2025-71176MEDIUM6.8pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users...
CVE-2025-27380HIGH7.6HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attac...
CVE-2025-27379MEDIUM4.6A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker...
CVE-2025-27378CRITICAL9.8AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f...
CVE-2025-27377MEDIUM5.3Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capa...
CVE-2025-69285MEDIUM6.1SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a mi...
CVE-2025-69209MEDIUM6.9ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in ...
CVE-2025-68141HIGH7.4EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes`...
CVE-2025-68140MEDIUM4.3EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b...
CVE-2025-68139MEDIUM4.3EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat...
CVE-2025-68138MEDIUM4.7EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol....
CVE-2025-68137HIGH8.3EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse...
CVE-2025-68136HIGH7.4EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates...
CVE-2025-13465MEDIUM5.3Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta...
CVE-2025-12781MEDIUM5.3When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the...
CVE-2025-68135MEDIUM6.5EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by...
CVE-2025-68134HIGH7.4EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors ...
CVE-2025-68132MEDIUM4.6EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now