2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68461MEDIUM6.1Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani...
CVE-2025-68460HIGH7.5Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML sty...
CVE-2025-12885MEDIUM6.4The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-14856HIGH8.8A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function o...
CVE-2025-14841LOW3.3A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHand...
CVE-2025-14837HIGH7.2A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/sitecon...
CVE-2025-14202HIGH8.2A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG f...
CVE-2025-68435CRITICAL9.1Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne...
CVE-2025-68434HIGH8.8Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68433HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo...
CVE-2025-68432HIGH7.3Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La...
CVE-2025-68429MEDIUM5.3Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present ...
CVE-2025-68147HIGH8.1Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-68145CRITICAL9.1In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat...
CVE-2025-68144HIGH7.1In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments...
CVE-2025-68143HIGH8.8Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp...
CVE-2025-66029HIGH7.6Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti...
CVE-2025-14836LOW2.7A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_sa...
CVE-2025-14834HIGH8.8A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /c...
CVE-2025-14833CRITICAL9.8A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u...
CVE-2025-14319——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-14268——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-68401MEDIUM4.8ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/...
CVE-2025-68400HIGH8.8ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo...
CVE-2025-68399MEDIUM5.4ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now