2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-45868HIGH8.8LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo...
CVE-2025-71388HIGH7.6stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ...
CVE-2025-71377HIGH8.7stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me...
CVE-2025-56365HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co...
CVE-2025-56364HIGH7.5A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin...
CVE-2025-56363HIGH7.5A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi...
CVE-2025-56362HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev...
CVE-2025-56361HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev...
CVE-2025-53379HIGH7.5A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio...
CVE-2025-40945HIGH8.5A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),...
CVE-2025-45869HIGH7.3LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti...
CVE-2025-6784HIGH8.8The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ...
CVE-2025-30007HIGH8.8HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat...
CVE-2025-70796HIGH7.5An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc....
CVE-2025-45422HIGH8.1Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak...
CVE-2025-63579HIGH7.5Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu...
CVE-2025-3110HIGH7.5OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at...
CVE-2025-59617HIGH7.3Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2025-59616HIGH7.8Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea...
CVE-2025-59615HIGH7.8Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe...
CVE-2025-53831HIGH8.2DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application o...
CVE-2025-53829HIGH8ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack...
CVE-2025-53828HIGH8.5SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli...
CVE-2025-13475HIGH7.3In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be...
CVE-2025-71380HIGH8.8The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n ru...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now