2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11369MEDIUM4.3The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unau...
CVE-2025-11009MEDIUM5.1Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all vers...
CVE-2025-53524HIGH8.4Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi...
CVE-2025-14701HIGH7.1An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated...
CVE-2025-14700CRITICAL9.9An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authentica...
CVE-2025-34288MEDIUM6.7Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between s...
CVE-2025-14766HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp...
CVE-2025-14765HIGH8.8Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap ...
CVE-2025-68274HIGH7.5SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp...
CVE-2025-64520MEDIUM4.3GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unau...
CVE-2025-53619CRITICAL9.1An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ...
CVE-2025-53618CRITICAL9.1An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ...
CVE-2025-52582HIGH7.5An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0...
CVE-2025-48429CRITICAL9.1An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A sp...
CVE-2025-14466MEDIUM6.9A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthe...
CVE-2025-0852Rejected reason: Voluntarily withdrawn
CVE-2025-8872HIGH7.1On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process...
CVE-2025-65834CRITICAL9.8Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT projec...
CVE-2025-13532MEDIUM6.2Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the sele...
CVE-2025-68270CRITICAL9.9The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours...
CVE-2025-68156HIGH7.5Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E...
CVE-2025-68155HIGH7.5@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find...
CVE-2025-68154HIGH8.1systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct...
CVE-2025-68150MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2025-68146MEDIUM6.5filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now