2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61666HIGH8.7Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and n...
CVE-2025-61600HIGH7.5Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil...
CVE-2025-61665HIGH7.5WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken ...
CVE-2025-61604HIGH7.1WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S...
CVE-2025-61595HIGH8.8MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4...
CVE-2025-10653HIGH8.6An unauthenticated debug port may allow access to the device file system.
CVE-2025-59835HIGH8.6LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attac...
CVE-2025-54315HIGH7.1The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
CVE-2025-49090HIGH7.1The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient...
CVE-2025-32942HIGH7.2SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.
CVE-2025-60663HIGH7.5Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan f...
CVE-2025-59409HIGH7.5Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck...
CVE-2025-59405HIGH7.5The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and S...
CVE-2025-34208HIGH7.5Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords u...
CVE-2025-60662HIGH7.5Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan...
CVE-2025-60660HIGH7.5Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan func...
CVE-2025-56161HIGH7.5YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment...
CVE-2025-59745HIGH7.5Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cr...
CVE-2025-59744HIGH7.5Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only withi...
CVE-2025-11240HIGH7.2An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker...
CVE-2025-61735HIGH7.3Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5...
CVE-2025-61734HIGH7.5Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's ...
CVE-2025-61733HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin...
CVE-2025-54289HIGH8.1Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions...
CVE-2025-54286HIGH8.8Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now