2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67780MEDIUM4.2SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un...
CVE-2025-66452MEDIUM6.1LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing...
CVE-2025-66451MEDIUM6.5LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests...
CVE-2025-66450MEDIUM5.4LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic...
CVE-2025-66446HIGH7.5MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow...
CVE-2025-66419CRITICAL10MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to ...
CVE-2025-64721CRITICAL10Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1....
CVE-2025-34506HIGH8.8WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator...
CVE-2025-34504MEDIUM6.1KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ...
CVE-2025-34499MEDIUM6.9AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten...
CVE-2025-13668MEDIUM6.7A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.
CVE-2025-66590CRITICAL9.8In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker t...
CVE-2025-66589CRITICAL9.1In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to...
CVE-2025-66588CRITICAL9.8In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by a...
CVE-2025-66587——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-66586HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp...
CVE-2025-66585HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup...
CVE-2025-66584——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-66429HIGH8.8An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow...
CVE-2025-64702MEDIUM5.3quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al...
CVE-2025-55816MEDIUM6.1HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
CVE-2025-14538LOW3.5A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCust...
CVE-2025-14537CRITICAL9.8A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some ...
CVE-2025-14293MEDIUM6.5The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ...
CVE-2025-13664MEDIUM6.7A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now