2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64513CRITICAL9.3Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a...
CVE-2025-64512HIGH7.8Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documen...
CVE-2025-64509HIGH7.5Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope...
CVE-2025-64508HIGH7.5Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli strea...
CVE-2025-64507HIGH7.8Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu...
CVE-2025-64504MEDIUM5Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2...
CVE-2025-64502MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `exp...
CVE-2025-64501HIGH7.6ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be...
CVE-2025-64484HIGH8.5OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat...
CVE-2025-64183HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64182HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64181HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64167MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-sit...
CVE-2025-63397MEDIUM6.5Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence ...
CVE-2025-62780MEDIUM5.4changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha...
CVE-2025-49145MEDIUM6.5Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri...
CVE-2025-63617MEDIUM6.5ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulne...
CVE-2025-63296MEDIUM6.5KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot...
CVE-2025-48878MEDIUM4.3Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct...
CVE-2025-48065MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-48055MEDIUM5.4Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse ...
CVE-2025-63384MEDIUM6.5A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exce...
CVE-2025-63149HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list...
CVE-2025-60876MEDIUM6.5BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/que...
CVE-2025-56503MEDIUM6.5An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now