2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14777MEDIUM6A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for author...
CVE-2025-13956MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-62849CRITICAL9.8An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ...
CVE-2025-62848HIGH7.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ...
CVE-2025-62847HIGH7.5An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP op...
CVE-2025-59385CRITICAL9.8An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. T...
CVE-2025-14749HIGH8.8A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_...
CVE-2025-14748MEDIUM5.4A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_...
CVE-2025-14747MEDIUM6.5A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTS...
CVE-2025-14746MEDIUM6.5A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the componen...
CVE-2025-68115MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2025-68113MEDIUM6.5ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari...
CVE-2025-67874MEDIUM6.5ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass...
CVE-2025-67751HIGH7.2ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in th...
CVE-2025-67748HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missi...
CVE-2025-67747HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` ...
CVE-2025-67744CRITICAL9.6DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to versi...
CVE-2025-67736HIGH7.2The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manage...
CVE-2025-67735MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final...
CVE-2025-67722HIGH7.8FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and ...
CVE-2025-67715MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti...
CVE-2025-67492MEDIUM5.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for m...
CVE-2025-66449HIGH8.8ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica...
CVE-2025-14758MEDIUM6.5Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows ...
CVE-2025-9460HIGH7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulner...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now