2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54322CRITICAL9.8Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete...
CVE-2025-15107HIGH8.1A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio...
CVE-2025-15106MEDIUM4.3A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi...
CVE-2025-15105MEDIUM5.9A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu...
CVE-2025-68952CRITICAL9.8Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been ident...
CVE-2025-68948HIGH8.1SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note ...
CVE-2025-68927MEDIUM6.1Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in...
CVE-2025-59946HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss...
CVE-2025-68932CRITICAL9.8FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n...
CVE-2025-68474HIGH7.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ...
CVE-2025-68473HIGH8.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ...
CVE-2025-68148HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny ...
CVE-2025-66203CRITICAL9.1StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerabili...
CVE-2025-68697MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ...
CVE-2025-68668CRITICAL9.9n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability e...
CVE-2025-67729HIGH8.8LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization...
CVE-2025-61914MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner...
CVE-2025-66737MEDIUM4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi...
CVE-2025-67015HIGH7.5Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows atta...
CVE-2025-67014HIGH7.5Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauth...
CVE-2025-67013MEDIUM6.5The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme...
CVE-2025-66738HIGH8.8An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a ...
CVE-2025-57403HIGH7.5Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application...
CVE-2025-13158CRITICAL9.3Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to m...
CVE-2025-67349MEDIUM6.1A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now