2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64114MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrato...
CVE-2025-62596CRITICAL10Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie...
CVE-2025-62161CRITICAL10Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul...
CVE-2025-55278HIGH8.1Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep...
CVE-2025-12779HIGH8.8Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,...
CVE-2025-63585MEDIUM6.5OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp para...
CVE-2025-60784MEDIUM6.5A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou paramet...
CVE-2025-63334CRITICAL9.8PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm...
CVE-2025-10853MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to i...
CVE-2025-63418MEDIUM6.1A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitra...
CVE-2025-63417HIGH7.2A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authe...
CVE-2025-63416CRITICAL9.1** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the Self...
CVE-2025-5770MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products du...
CVE-2025-56232MEDIUM6.8GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or ...
CVE-2025-55343CRITICAL9.9Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d...
CVE-2025-55342MEDIUM5.3Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all...
CVE-2025-55341MEDIUM6.5Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.
CVE-2025-43418MEDIUM4.6This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS...
CVE-2025-31954MEDIUM4.3HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to pro...
CVE-2025-12745HIGH7.8A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_a...
CVE-2025-11093HIGH7.2An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal...
CVE-2025-56231CRITICAL9.1Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta...
CVE-2025-10907HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte...
CVE-2025-10713CRITICAL9.1An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML par...
CVE-2025-63248HIGH7.5DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now