2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9803HIGH8.8lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth ...
CVE-2025-65951HIGH8.7Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim...
CVE-2025-65944MEDIUM5.1Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js appl...
CVE-2025-64761HIGH7.2OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could ...
CVE-2025-65018HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-64720HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-64506MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-64505MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-62155HIGH8.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2025-10144MEDIUM6.5The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri...
CVE-2025-63674MEDIUM6.8An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary c...
CVE-2025-54563HIGH7.5An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-54347CRITICAL9.9A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6...
CVE-2025-54341MEDIUM5.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Ha...
CVE-2025-54338HIGH7.5An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-63498MEDIUM6.1alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
CVE-2025-52538HIGH8Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p...
CVE-2025-48511MEDIUM5.5Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti...
CVE-2025-48510HIGH7.1Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confi...
CVE-2025-36150HIGH7.5IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-29933MEDIUM5.5Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a...
CVE-2025-0007MEDIUM5.7Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user s...
CVE-2025-0003HIGH7.3Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition poten...
CVE-2025-64048MEDIUM6.1YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulner...
CVE-2025-64047MEDIUM6.1OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now