2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15514HIGH7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal mod...
CVE-2025-67146CRITICAL9.4Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)...
CVE-2025-29329CRITICAL9.8Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ...
CVE-2025-12420CRITICAL9.8A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona...
CVE-2025-67147CRITICAL9.8Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a...
CVE-2025-66802CRITICAL9.8Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive...
CVE-2025-51567CRITICAL9.1A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a...
CVE-2025-14470Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-68657MEDIUM6.4Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi...
CVE-2025-68656MEDIUM6.8Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r...
CVE-2025-68471MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68468MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68276MEDIUM5.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68622MEDIUM6.8Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in ...
CVE-2025-68472CRITICAL9.1MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti...
CVE-2025-66689MEDIUM6.5A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra...
CVE-2025-63314CRITICAL10A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a...
CVE-2025-46070CRITICAL9.8An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon...
CVE-2025-46068HIGH8.8An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
CVE-2025-46067HIGH8.2An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information v...
CVE-2025-46066CRITICAL9.9An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
CVE-2025-71063HIGH7.5Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.
CVE-2025-67813MEDIUM5.3Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica...
CVE-2025-66939MEDIUM5.4Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via ...
CVE-2025-65553MEDIUM6.5D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now