2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66402MEDIUM6.5Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025...
CVE-2025-58173HIGH8.8FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `lan...
CVE-2025-14731HIGH7.2A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the l...
CVE-2025-14593HIGH7.8A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulne...
CVE-2025-10900HIGH7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne...
CVE-2025-10899HIGH7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne...
CVE-2025-10898HIGH7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne...
CVE-2025-10889HIGH7.8A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnera...
CVE-2025-10888HIGH7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne...
CVE-2025-10887HIGH7.8A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi...
CVE-2025-10886HIGH7.8A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi...
CVE-2025-10884HIGH7.8AA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vul...
CVE-2025-10883HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read v...
CVE-2025-10882HIGH7.8AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnera...
CVE-2025-10881HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vu...
CVE-2025-9122MEDIUM5.3Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi...
CVE-2025-9121HIGH8.8Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and...
CVE-2025-14730HIGH7.2A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown f...
CVE-2025-14729HIGH7.2A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save...
CVE-2025-64725CRITICAL9.8Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a...
CVE-2025-59947CRITICAL9NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBL...
CVE-2025-55895CRITICAL9.1TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to I...
CVE-2025-14722LOW2.4A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1. This impacts the funct...
CVE-2025-67809MEDIUM4.7An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i...
CVE-2025-55703LOW3.3An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outd...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now