2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14746MEDIUM6.5A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the componen...
CVE-2025-68115MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2025-68113MEDIUM6.5ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari...
CVE-2025-67874MEDIUM6.5ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass...
CVE-2025-67751HIGH7.2ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in th...
CVE-2025-67748HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missi...
CVE-2025-67747HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` ...
CVE-2025-67744CRITICAL9.6DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to versi...
CVE-2025-67736HIGH7.2The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manage...
CVE-2025-67735MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final...
CVE-2025-67722HIGH7.8FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and ...
CVE-2025-67715MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti...
CVE-2025-67492MEDIUM5.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for m...
CVE-2025-66449HIGH8.8ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica...
CVE-2025-14758MEDIUM6.5Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows ...
CVE-2025-9460HIGH7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulner...
CVE-2025-9459HIGH7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulner...
CVE-2025-9457HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabili...
CVE-2025-9456HIGH7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerab...
CVE-2025-9455HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vu...
CVE-2025-9454HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-9453HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-9452HIGH7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerab...
CVE-2025-66482MEDIUM6.5Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a ...
CVE-2025-66407MEDIUM5Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add n...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now