2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53896HIGH8.1Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus...
CVE-2025-66219CRITICAL9.8willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm...
CVE-2025-66201HIGH8.1LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-sid...
CVE-2025-66036MEDIUM6.1Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cro...
CVE-2025-66034CRITICAL9.8fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttool...
CVE-2025-66027MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil...
CVE-2025-65113MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerabi...
CVE-2025-65112CRITICAL9.8PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubN...
CVE-2025-64715MEDIUM5.5Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1....
CVE-2025-13683MEDIUM6.5Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affec...
CVE-2025-12183HIGH8.8Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service ...
CVE-2025-59792MEDIUM5.3Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks...
CVE-2025-59790MEDIUM5.4Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v...
CVE-2025-51736MEDIUM6.3File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51735HIGH7.5CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51734MEDIUM5.4Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51733MEDIUM5.5Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-12638HIGH8Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin...
CVE-2025-11156MEDIUM5.9Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex...
CVE-2025-12143MEDIUM6.9Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.
CVE-2025-13771HIGH7.1WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit ...
CVE-2025-13770HIGH7.1WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2025-13769HIGH7.1WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2025-13768HIGH8.8WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in...
CVE-2025-66386MEDIUM4.1app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now