2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66412MEDIUM5.4Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2025-66410CRITICAL9.1Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file...
CVE-2025-66405CRITICAL9.8Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the ...
CVE-2025-66403MEDIUM5.4FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, ...
CVE-2025-66401CRITICAL9.8MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca...
CVE-2025-66400MEDIUM5.3mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classna...
CVE-2025-66313HIGH7.2ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL in...
CVE-2025-66312MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66311MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66310MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66309MEDIUM6.1This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66308MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66307MEDIUM5.3This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66306MEDIUM6.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerabi...
CVE-2025-66305MEDIUM4.9Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the...
CVE-2025-66304HIGH7.2Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section...
CVE-2025-66303MEDIUM4.9Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified i...
CVE-2025-66302MEDIUM6.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CM...
CVE-2025-66301CRITICAL9.6Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical ...
CVE-2025-66300HIGH8.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can ...
CVE-2025-66299HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S...
CVE-2025-66298HIGH7.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav config...
CVE-2025-65622MEDIUM5.4Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user ...
CVE-2025-66297HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or e...
CVE-2025-66296HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now