2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71388HIGH7.6stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ...
CVE-2025-71377HIGH8.7stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me...
CVE-2025-56365HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co...
CVE-2025-56364HIGH7.5A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin...
CVE-2025-56363HIGH7.5A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi...
CVE-2025-56362HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev...
CVE-2025-56361HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev...
CVE-2025-53379HIGH7.5A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio...
CVE-2025-40945HIGH8.5A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),...
CVE-2025-45869HIGH7.3LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti...
CVE-2025-6784HIGH8.8The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ...
CVE-2025-30007HIGH8.8HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat...
CVE-2025-70796HIGH7.5An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc....
CVE-2025-45422HIGH8.1Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak...
CVE-2025-63579HIGH7.5Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu...
CVE-2025-3110HIGH7.5OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at...
CVE-2025-59617HIGH7.3Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2025-59616HIGH7.8Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea...
CVE-2025-59615HIGH7.8Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe...
CVE-2025-53831HIGH8.2DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application o...
CVE-2025-53829HIGH8ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack...
CVE-2025-53828HIGH8.5SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli...
CVE-2025-13475HIGH7.3In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be...
CVE-2025-71380HIGH8.8The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n ru...
CVE-2025-71375HIGH8.1picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now