2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68435CRITICAL9.1Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne...
CVE-2025-68434HIGH8.8Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68433HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo...
CVE-2025-68432HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La...
CVE-2025-68429MEDIUM5.3Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present ...
CVE-2025-68147HIGH8.1Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68145CRITICAL9.1In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat...
CVE-2025-68144HIGH7.1In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments...
CVE-2025-68143HIGH8.8Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp...
CVE-2025-66029HIGH7.6Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti...
CVE-2025-14836LOW2.7A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_sa...
CVE-2025-14834HIGH8.8A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /c...
CVE-2025-14833CRITICAL9.8A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u...
CVE-2025-14319Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-14268Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-68401MEDIUM4.8ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/...
CVE-2025-68400HIGH8.8ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo...
CVE-2025-68399MEDIUM5.4ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting...
CVE-2025-68275MEDIUM4.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnera...
CVE-2025-68129HIGH7.5Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the a...
CVE-2025-68118CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in Free...
CVE-2025-68114CRITICAL9.8Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat...
CVE-2025-68112HIGH8.8ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in Churc...
CVE-2025-68111HIGH7.2ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i...
CVE-2025-68110HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now