2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62171HIGH7.5ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick ...
CVE-2025-62168HIGH7.5Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential...
CVE-2025-62356HIGH7.5A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local f...
CVE-2025-59043HIGH7.5OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects aft...
CVE-2025-26625HIGH8.6Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re...
CVE-2025-11905HIGH8.8A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the...
CVE-2025-55085HIGH7.5In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsi...
CVE-2025-11904HIGH7.2A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo...
CVE-2025-48044HIGH8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6...
CVE-2025-11903HIGH7.2A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cm...
CVE-2025-11902HIGH7.2A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findFie...
CVE-2025-55094HIGH7.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-55087HIGH7.5In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an ou...
CVE-2025-11898HIGH8.7Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t...
CVE-2025-6892HIGH8.7An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw i...
CVE-2025-62506HIGH8.1MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege es...
CVE-2025-62504HIGH7.5Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain...
CVE-2025-11864HIGH7.3A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply...
CVE-2025-62428HIGH8.8Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host ...
CVE-2025-62427HIGH8.7The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request For...
CVE-2025-62425HIGH8.3MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and ...
CVE-2025-62423HIGH7.2ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vul...
CVE-2025-62417HIGH7.8Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character...
CVE-2025-61553HIGH8.2An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (...
CVE-2025-11853HIGH8.1A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now