2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68109HIGH7.2ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe...
CVE-2025-67877HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the ...
CVE-2025-67876MEDIUM5.4ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in Church...
CVE-2025-67875MEDIUM5.4ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to ...
CVE-2025-67873HIGH7.8Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a use...
CVE-2025-67794MEDIUM6.1An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and fi...
CVE-2025-67791CRITICAL9.8An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete co...
CVE-2025-14832CRITICAL9.8A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct...
CVE-2025-67793CRITICAL9.8An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "M...
CVE-2025-67792HIGH7.8An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ...
CVE-2025-67790HIGH7.5An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use...
CVE-2025-67789MEDIUM5.3An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users...
CVE-2025-67493CRITICAL9Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e...
CVE-2025-66647CRITICAL9.8RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2025-59849MEDIUM6.1Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lo...
CVE-2025-55254MEDIUM4.8Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.032...
CVE-2025-53000HIGH7.8The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions...
CVE-2025-46292MEDIUM5.5This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26...
CVE-2025-46291HIGH7.8A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An ...
CVE-2025-46288MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS T...
CVE-2025-46283MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, ...
CVE-2025-46282MEDIUM5.5The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app...
CVE-2025-46281HIGH8.8A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macO...
CVE-2025-46279LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS...
CVE-2025-46278MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now