2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66295HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new use...
CVE-2025-66294HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists ...
CVE-2025-66206HIGH8.6Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path...
CVE-2025-66205CRITICAL9.8Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to err...
CVE-2025-65840HIGH8.8PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
CVE-2025-65621MEDIUM5.4Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes...
CVE-2025-58044MEDIUM6.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and ...
CVE-2025-55749HIGH7.5XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is usin...
CVE-2025-65838HIGH7.5PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
CVE-2025-65836CRITICAL9.1PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
CVE-2025-63317MEDIUM5.4Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization ap...
CVE-2025-51683CRITICAL9.8A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL...
CVE-2025-51682CRITICAL9.8mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and ga...
CVE-2025-12756MEDIUM4.3Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe...
CVE-2025-65407MEDIUM6.5A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta...
CVE-2025-63365HIGH7.1SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file proces...
CVE-2025-34297HIGH8.6KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platf...
CVE-2025-11772MEDIUM6.6A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w...
CVE-2025-13837MEDIUM5.5When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file...
CVE-2025-13836HIGH7.5When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content...
CVE-2025-13835MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc...
CVE-2025-13653MEDIUM4.3In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which ...
CVE-2025-7007HIGH7.5NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed W...
CVE-2025-65794Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-65793Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now