2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66385CRITICAL9.4UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges ...
CVE-2025-66384HIGH8.2app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela...
CVE-2025-66382MEDIUM5.5In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing ...
CVE-2025-66372LOW2.8Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
CVE-2025-66371MEDIUM5Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XM...
CVE-2025-66370MEDIUM5Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to...
CVE-2025-64312HIGH7.5Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma...
CVE-2025-58311HIGH7.1UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availabili...
CVE-2025-58308LOW3.3Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi...
CVE-2025-58305MEDIUM5.5Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m...
CVE-2025-58304MEDIUM5.5Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma...
CVE-2025-58302MEDIUM5.5Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2025-13737MEDIUM4.3The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2025-64315HIGH7.1Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-64314MEDIUM5.5Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-64313MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a...
CVE-2025-64311MEDIUM5.5Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect...
CVE-2025-58316MEDIUM5.5DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-58315MEDIUM5.5Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-58314HIGH7.1Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner...
CVE-2025-58312MEDIUM5.5Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2025-58310MEDIUM5.5Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may...
CVE-2025-58309HIGH7.1Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w...
CVE-2025-58307MEDIUM5.5UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af...
CVE-2025-58303MEDIUM5.5UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now