2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14111HIGH8.1A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa...
CVE-2025-14108HIGH8.8A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.O...
CVE-2025-14107HIGH8.8A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function ...
CVE-2025-14106HIGH8.8A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of th...
CVE-2025-13426HIGH8.7A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/ja...
CVE-2025-8148MEDIUM4.2An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with a...
CVE-2025-14105MEDIUM4.3A vulnerability was determined in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. This impacts an unknown function of the ...
CVE-2025-66644CRITICAL9.8Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2...
CVE-2025-66624HIGH7.5BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat...
CVE-2025-66623HIGH7.4Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F...
CVE-2025-66581MEDIUM6.5Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, ...
CVE-2025-66577MEDIUM5.3cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow...
CVE-2025-66570CRITICAL9.8cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow...
CVE-2025-46603HIGH7.5Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentic...
CVE-2025-66566HIGH8.2yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor...
CVE-2025-66562CRITICAL9.6TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Exec...
CVE-2025-66558MEDIUM4.3Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing owne...
CVE-2025-66557MEDIUM4.3Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2025-66556MEDIUM4.3Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat pe...
CVE-2025-66554MEDIUM5.4Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5...
CVE-2025-66553MEDIUM4.3Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated u...
CVE-2025-66551MEDIUM4.3Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious use...
CVE-2025-66549LOW2.7Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside ...
CVE-2025-66548MEDIUM5.5Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2025-66545MEDIUM4.3Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.1...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now