2025 CVE Vulnerabilities

45,199 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66019MEDIUM6.6pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability...
CVE-2025-65963MEDIUM5.4Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient...
CVE-2025-65957HIGH8.8Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_...
CVE-2025-65956MEDIUM5.4Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t...
CVE-2025-65953MEDIUM6NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA...
CVE-2025-65952HIGH8.7Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p...
CVE-2025-65942LOW2.7VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1....
CVE-2025-64713HIGH7.4WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-...
CVE-2025-64704MEDIUM5.5WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is...
CVE-2025-13597CRITICAL9.8The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual...
CVE-2025-13595CRITICAL9.8The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu...
CVE-2025-63735MEDIUM6.1A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the th...
CVE-2025-62703HIGH8.8Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Da...
CVE-2025-21621MEDIUM6.1GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a refle...
CVE-2025-58360CRITICAL9.8GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2....
CVE-2025-51746CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjso...
CVE-2025-51745CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization...
CVE-2025-51744CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserializatio...
CVE-2025-51743CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to...
CVE-2025-51741HIGH7.5An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to...
CVE-2025-9624HIGH7.5A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input...
CVE-2025-66017HIGH8.2CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab...
CVE-2025-66016CRITICAL9.3CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab...
CVE-2025-65965HIGH8.2Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found i...
CVE-2025-65647MEDIUM4.3Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows info...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now