2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60889CRITICAL9.8Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to e...
CVE-2025-60887MEDIUM5.3An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m...
CVE-2025-67223HIGH7.5The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w...
CVE-2025-48431HIGH7.5Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach...
CVE-2025-10539MEDIUM4.8Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p...
CVE-2025-69428HIGH7.5An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi...
CVE-2025-69689HIGH8.8The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dial...
CVE-2025-54505LOW2A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa...
CVE-2025-15626MEDIUM5.3Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
CVE-2025-67259MEDIUM6.5A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user...
CVE-2025-59308MEDIUM4.7In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ...
CVE-2025-61872MEDIUM6.1Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer...
CVE-2025-62233MEDIUM6.3Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi...
CVE-2025-11762MEDIUM4.3The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2025-62373CRITICAL9.8Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0...
CVE-2025-50229CRITICAL9.8Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
CVE-2025-70994HIGH7.3Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent...
CVE-2025-66286MEDIUM4.7An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS ...
CVE-2025-13763MEDIUM5.7Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application ...
CVE-2025-62110MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Resc...
CVE-2025-62104MEDIUM4.3Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Con...
CVE-2025-10549MEDIUM5.1EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in...
CVE-2025-36074HIGH7.2IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to m...
CVE-2025-9957LOW2.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-6016MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now