2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7985HIGH7.8Ashlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows re...
CVE-2025-7984HIGH7.8Ashlar-Vellum Cobalt AR File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-7983HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili...
CVE-2025-7982HIGH7.8Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2025-7981HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability a...
CVE-2025-7980HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-7979HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-7978HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability a...
CVE-2025-7977HIGH7.8Ashlar-Vellum Cobalt LI File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-10618HIGH8.8A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue i...
CVE-2025-10617HIGH8.8A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown...
CVE-2025-10616HIGH8.8A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file ...
CVE-2025-59353HIGH7.5Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain...
CVE-2025-59348HIGH7.5Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceF...
CVE-2025-10615HIGH8.8A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /adm...
CVE-2025-59416HIGH7.2The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since t...
CVE-2025-10613HIGH8.8A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown functi...
CVE-2025-10608HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file ...
CVE-2025-59341HIGH7.7esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion...
CVE-2025-58432HIGH7.8ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all ...
CVE-2025-35436HIGH7.5CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote...
CVE-2025-35433HIGH8.8CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a ...
CVE-2025-35432HIGH7.5CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker...
CVE-2025-10602HIGH8.8A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknow...
CVE-2025-40933HIGH7.5Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now