2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57109MEDIUM6.5Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr...
CVE-2025-52180MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated atta...
CVE-2025-52179MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated at...
CVE-2025-36137HIGH7.2IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 throu...
CVE-2025-64118MEDIUM6.1node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uni...
CVE-2025-64116MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts...
CVE-2025-64115MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use...
CVE-2025-64112HIGH8Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Ta...
CVE-2025-62266MEDIUM6.1By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20...
CVE-2025-56313MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3...
CVE-2025-64096HIGH8.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-63885MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web sc...
CVE-2025-62795HIGH7.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts ...
CVE-2025-62726HIGH8.8n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th...
CVE-2025-61196HIGH8.8An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa...
CVE-2025-61121HIGH7.5Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., ...
CVE-2025-61120HIGH7.5AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con...
CVE-2025-61119HIGH7.5Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont...
CVE-2025-61114HIGH7.52nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., con...
CVE-2025-60950MEDIUM6.1An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to ex...
CVE-2025-60319MEDIUM6.5PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttac...
CVE-2025-12060HIGH8.9The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path ...
CVE-2025-62712HIGH8.1JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions...
CVE-2025-61118HIGH7.5mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper acces...
CVE-2025-61117HIGH7.5Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an impro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now