2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-63914MEDIUM6.5An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui....
CVE-2025-56400HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, a...
CVE-2025-52539HIGH7.3A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced ...
CVE-2025-0005HIGH7.3Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p...
CVE-2025-36112MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1....
CVE-2025-13466MEDIUM5.5body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large n...
CVE-2025-13609HIGH8.2A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using ...
CVE-2025-63958CRITICAL9.8MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is acc...
CVE-2025-63953MEDIUM6.5A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta...
CVE-2025-63952MEDIUM5.7A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta...
CVE-2025-63435MEDIUM4.3Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side end...
CVE-2025-63434HIGH8.8The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downl...
CVE-2025-63433MEDIUM4.6Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt updat...
CVE-2025-63432MEDIUM4.6Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fai...
CVE-2025-13594Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-13511Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-60917MEDIUM4.6A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti...
CVE-2025-60916MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti...
CVE-2025-60915HIGH8.1An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allo...
CVE-2025-60914MEDIUM4.6Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensit...
CVE-2025-60638HIGH7.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ...
CVE-2025-60633MEDIUM6.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_Subs...
CVE-2025-60632MEDIUM6.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ...
CVE-2025-56423MEDIUM5.3An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attac...
CVE-2025-56401HIGH7.6ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now