2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68454HIGH8.8Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar...
CVE-2025-68437MEDIUM6.8Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16...
CVE-2025-68436MEDIUM6.5Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16...
CVE-2025-68428HIGH7.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa...
CVE-2025-67732MEDIUM6.5Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the...
CVE-2025-66648MEDIUM6.1vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites tha...
CVE-2025-65110CRITICAL9.3Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2025-61916MEDIUM6.6Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3....
CVE-2025-64425HIGH8.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions ...
CVE-2025-64424HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions ...
CVE-2025-64423HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions ...
CVE-2025-64422MEDIUM4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting...
CVE-2025-67427MEDIUM6.5A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to...
CVE-2025-67419HIGH7.5A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the appl...
CVE-2025-64421HIGH8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions ...
CVE-2025-64420HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions ...
CVE-2025-64419HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-69291Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2025-69290Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2025-67397CRITICAL9.1An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP reques...
CVE-2025-53966HIGH8.4An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211...
CVE-2025-52517MEDIUM5.9An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-52516MEDIUM6.2An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-52515MEDIUM5.1An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-49495HIGH8.4An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now