2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67500LOW3.7Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro...
CVE-2025-67499LOW3.6The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versi...
CVE-2025-64898MEDIUM5.3ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera...
CVE-2025-64897MEDIUM5.6ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low...
CVE-2025-61823MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61822MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61821MEDIUM6.8ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61813HIGH7.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61812HIGH8.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61811CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-61810HIGH8.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2025-61809CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61808CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T...
CVE-2025-67498——Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2025-67497——Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2025-67496MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-67495MEDIUM6.1ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS...
CVE-2025-13760——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-67494HIGH8.6ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f...
CVE-2025-66645HIGH7.5NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App....
CVE-2025-66039CRITICAL9.8FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to aut...
CVE-2025-65513HIGH7.5fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to...
CVE-2025-36437MEDIUM4.3IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai...
CVE-2025-34425MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext par...
CVE-2025-67489CRITICAL9.8@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to ar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now