2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66909HIGH7.5Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerabilit...
CVE-2025-66908MEDIUM5.3Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR ...
CVE-2025-50681HIGH7.5igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft...
CVE-2025-14952CRITICAL9.8A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /...
CVE-2025-14951CRITICAL9.8A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk...
CVE-2025-14950CRITICAL9.8A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio...
CVE-2025-1928CRITICAL9.1Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online...
CVE-2025-14946MEDIUM4.8A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Unifor...
CVE-2025-14882LOW3.8An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intende...
CVE-2025-14881LOW3.8Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not ...
CVE-2025-1927HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al...
CVE-2025-1885MEDIUM5.4URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food ...
CVE-2025-14847HIGH8.7Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe...
CVE-2025-66524HIGH8.8Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di...
CVE-2025-14455MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up t...
CVE-2025-12361MEDIUM4.3The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne...
CVE-2025-14151HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par...
CVE-2025-11747MEDIUM6.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts sh...
CVE-2025-66522MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud ...
CVE-2025-66521MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature....
CVE-2025-66520MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonli...
CVE-2025-66519MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A...
CVE-2025-66502MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A cra...
CVE-2025-66501MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of th...
CVE-2025-66500MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now