2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6796HIGH7.5Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability al...
CVE-2025-6795HIGH7.5Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability ...
CVE-2025-6714HIGH7.5MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete dat...
CVE-2025-6663HIGH7.8GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-5987HIGH8.1A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust th...
CVE-2025-6209HIGH7.5A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the...
CVE-2025-7127HIGH7.2A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System up to 1.0. This ...
CVE-2025-7126HIGH7.2A vulnerability, which was classified as critical, has been found in itsourcecode Employee Management System up to 1.0. ...
CVE-2025-7125HIGH7.2A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this ...
CVE-2025-7124HIGH8.8A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown f...
CVE-2025-7123HIGH7.2A vulnerability was found in Campcodes Complaint Management System 1.0. It has been rated as critical. This issue affect...
CVE-2025-6386HIGH7.5The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within t...
CVE-2025-3466HIGH7.2langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbi...
CVE-2025-3262HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, ...
CVE-2025-3225HIGH7.5An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-...
CVE-2025-3046HIGH7.5A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allo...
CVE-2025-7121HIGH8.8A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects...
CVE-2025-3920HIGH8.5A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These...
CVE-2025-7118HIGH8.8A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affec...
CVE-2025-7117HIGH8.8A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknow...
CVE-2025-7116HIGH7.5A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of...
CVE-2025-7115HIGH7.3A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr...
CVE-2025-7114HIGH7.5A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri...
CVE-2025-53473HIGH7.3Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulne...
CVE-2025-7145HIGH8.6ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers wit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now