2025 CVE Vulnerabilities

45,155 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14180HIGH7.5In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w...
CVE-2025-14178HIGH8.2In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, ...
CVE-2025-14177HIGH7.5In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, ...
CVE-2025-15109HIGH7.3A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of ...
CVE-2025-15108LOW3.7A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown ...
CVE-2025-54322CRITICAL9.8Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete...
CVE-2025-15107HIGH8.1A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio...
CVE-2025-15106MEDIUM4.3A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi...
CVE-2025-15105MEDIUM5.9A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu...
CVE-2025-68952CRITICAL9.8Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been ident...
CVE-2025-68948HIGH8.1SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note ...
CVE-2025-68927MEDIUM6.1Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in...
CVE-2025-59946HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss...
CVE-2025-68932CRITICAL9.8FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n...
CVE-2025-68474HIGH7.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ...
CVE-2025-68473HIGH8.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ...
CVE-2025-68148HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny ...
CVE-2025-66203CRITICAL9.1StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerabili...
CVE-2025-68697MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ...
CVE-2025-68668CRITICAL9.9n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability e...
CVE-2025-67729HIGH8.8LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization...
CVE-2025-61914MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner...
CVE-2025-66737MEDIUM4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi...
CVE-2025-67015HIGH7.5Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows atta...
CVE-2025-67014HIGH7.5Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauth...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now