2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66236HIGH7.5Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate ...
CVE-2025-15632LOW3.5A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat....
CVE-2025-15441MEDIUM6.8The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ...
CVE-2025-66447MEDIUM4.7Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ...
CVE-2025-44560CRITICAL9.8owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.
CVE-2025-5804HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58920HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato...
CVE-2025-58913HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-14545MEDIUM6.5The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ...
CVE-2025-59969HIGH7.1A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolki...
CVE-2025-13914HIGH8.1A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a...
CVE-2025-13926CRITICAL9.8An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request...
CVE-2025-70797MEDIUM6.1Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via...
CVE-2025-63238MEDIUM6.1A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio...
CVE-2025-70365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup...
CVE-2025-70364HIGH8.8An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod...
CVE-2025-15480CRITICAL9.1In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i...
CVE-2025-14551HIGH8.1In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation fai...
CVE-2025-70811MEDIUM4.3Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t...
CVE-2025-70810HIGH8.8Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t...
CVE-2025-62718CRITICAL9.9Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h...
CVE-2025-50228CRITICAL9.1Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
CVE-2025-45806MEDIUM6.1A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar...
CVE-2025-57735CRITICAL9.1When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t...
CVE-2025-62188HIGH7.5An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now