2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12875HIGH7.8A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems...
CVE-2025-64431HIGH8.7Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direc...
CVE-2025-36186HIGH7.8IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations co...
CVE-2025-33012HIGH8.8IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux coul...
CVE-2025-2534HIGH7.5IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ...
CVE-2025-9458HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili...
CVE-2025-64430HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2....
CVE-2025-64347HIGH7.5Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. ...
CVE-2025-57698HIGH7.5AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the ...
CVE-2025-63783HIGH7.6A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet...
CVE-2025-58469HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can the...
CVE-2025-58464HIGH7.5A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit...
CVE-2025-54167HIGH7.2A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains a...
CVE-2025-12861HIGH7.2A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the...
CVE-2025-12860HIGH7.2A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. ...
CVE-2025-12859HIGH7.2A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_...
CVE-2025-10968HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna...
CVE-2025-64343HIGH7.8(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 ...
CVE-2025-4519HIGH8.8The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala...
CVE-2025-64328HIGH7.2FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov...
CVE-2025-64184HIGH8.8Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constru...
CVE-2025-5483HIGH8.1The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi...
CVE-2025-58423HIGH8.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-se...
CVE-2025-12636HIGH7.1The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba...
CVE-2025-12036HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now