2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-51414HIGH8.8In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile ...
CVE-2025-3756HIGH7.1A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li...
CVE-2025-69627HIGH8.4Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript...
CVE-2025-69624HIGH7.5Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio...
CVE-2025-66769HIGH7.5A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-63743MEDIUM5.4Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a...
CVE-2025-31991CRITICAL9.8Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut...
CVE-2025-66236HIGH7.5Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate ...
CVE-2025-15632LOW3.5A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat....
CVE-2025-15441MEDIUM6.8The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ...
CVE-2025-66447MEDIUM4.7Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ...
CVE-2025-44560CRITICAL9.8owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.
CVE-2025-5804HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58920HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato...
CVE-2025-58913HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-14545MEDIUM6.5The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ...
CVE-2025-59969HIGH7.1A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolki...
CVE-2025-13914HIGH8.1A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a...
CVE-2025-13926CRITICAL9.8An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request...
CVE-2025-70797MEDIUM6.1Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via...
CVE-2025-63238MEDIUM6.1A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio...
CVE-2025-70365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup...
CVE-2025-70364HIGH8.8An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod...
CVE-2025-15480CRITICAL9.1In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i...
CVE-2025-14551HIGH8.1In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation fai...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now