2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67506CRITICAL9.8PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0....
CVE-2025-67485MEDIUM5.3mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se...
CVE-2025-67503Rejected reason: This CVE is a duplicate of another CVE.
CVE-2025-67502MEDIUM6.1Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t...
CVE-2025-67501HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-67500LOW3.7Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro...
CVE-2025-67499LOW3.6The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versi...
CVE-2025-64898MEDIUM5.3ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera...
CVE-2025-64897MEDIUM5.6ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low...
CVE-2025-61823MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61822MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61821MEDIUM6.8ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61813HIGH7.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61812HIGH8.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61811CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-61810HIGH8.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2025-61809CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61808CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T...
CVE-2025-67498Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2025-67497Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2025-67496MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-67495MEDIUM6.1ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS...
CVE-2025-13760Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-67494HIGH8.6ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f...
CVE-2025-66645HIGH7.5NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now