2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10915CRITICAL9.8The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check...
CVE-2025-66177HIGH8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models....
CVE-2025-66176HIGH8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products...
CVE-2025-15514HIGH7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal mod...
CVE-2025-67146CRITICAL9.4Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)...
CVE-2025-29329CRITICAL9.8Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ...
CVE-2025-12420CRITICAL9.8A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona...
CVE-2025-67147CRITICAL9.8Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a...
CVE-2025-66802CRITICAL9.8Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive...
CVE-2025-51567CRITICAL9.1A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a...
CVE-2025-14470——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-68657MEDIUM6.4Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi...
CVE-2025-68656MEDIUM6.8Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r...
CVE-2025-68471MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68468MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68276MEDIUM5.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68622MEDIUM6.8Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in ...
CVE-2025-68472CRITICAL9.1MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti...
CVE-2025-66689MEDIUM6.5A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra...
CVE-2025-63314CRITICAL10A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a...
CVE-2025-46070CRITICAL9.8An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon...
CVE-2025-46068HIGH8.8An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
CVE-2025-46067HIGH8.2An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information v...
CVE-2025-46066CRITICAL9.9An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
CVE-2025-71063HIGH7.5Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now