2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67743MEDIUM6.5Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1...
CVE-2025-15034CRITICAL9.8A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the f...
CVE-2025-68615CRITICAL9.8net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted pac...
CVE-2025-68614MEDIUM5.4LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule A...
CVE-2025-68480MEDIUM5.3Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions fro...
CVE-2025-68476HIGH8.2KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Re...
CVE-2025-68475HIGH7.5Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7....
CVE-2025-67436MEDIUM6.5Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inj...
CVE-2025-65857HIGH7.5An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetS...
CVE-2025-65856CRITICAL9.8Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21....
CVE-2025-34458HIGH8.7wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vul...
CVE-2025-34457HIGH8.7wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 694c954, contain a stack-based buffer over...
CVE-2025-66736HIGH7.1youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does n...
CVE-2025-66735HIGH7.5youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does n...
CVE-2025-65817HIGH8.8LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
CVE-2025-67418CRITICAL9.8ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded...
CVE-2025-67291MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute a...
CVE-2025-67290MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to e...
CVE-2025-65837MEDIUM5.4PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
CVE-2025-65790MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file ...
CVE-2025-67288CRITICAL10An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a ...
CVE-2025-63664HIGH7.5Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows un...
CVE-2025-63663HIGH7.5Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthori...
CVE-2025-63662HIGH7.5Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers t...
CVE-2025-26787MEDIUM4.7An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CL...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now