2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13120MEDIUM5.5A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/ar...
CVE-2025-64741CRITICAL9.8Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to...
CVE-2025-64740HIGH7.8Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an...
CVE-2025-64739HIGH7.5External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure ...
CVE-2025-64738MEDIUM5.5External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user ...
CVE-2025-62483HIGH7.5Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated use...
CVE-2025-62482MEDIUM6.1Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact int...
CVE-2025-30669MEDIUM6.5Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of inf...
CVE-2025-30662MEDIUM6.5Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6....
CVE-2025-13119MEDIUM6.5A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manip...
CVE-2025-13118MEDIUM4.3A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of ...
CVE-2025-13117MEDIUM5.3A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability...
CVE-2025-41069MEDIUM5.3Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to...
CVE-2025-13116MEDIUM5.3A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder o...
CVE-2025-13115MEDIUM5.3A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of t...
CVE-2025-13114MEDIUM5.3A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /c...
CVE-2025-40681MEDIUM5.1Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker...
CVE-2025-12818MEDIUM5.9Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network...
CVE-2025-12817LOW3.1Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against ...
CVE-2025-12765HIGH7.4pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver...
CVE-2025-12764HIGH7.5pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker t...
CVE-2025-12763HIGH8.8pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused ...
CVE-2025-12762CRITICAL9.8pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in serve...
CVE-2025-12377MEDIUM4.3The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2025-7704MEDIUM5.4Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now