2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11203LOW3.5LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to d...
CVE-2025-11202CRITICAL9.8win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-11201CRITICAL9.8MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows...
CVE-2025-11200CRITICAL9.8MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp...
CVE-2025-10934HIGH7.8GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-10925HIGH7.8GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2025-10924HIGH7.8GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to...
CVE-2025-10923HIGH7.8GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ...
CVE-2025-10922HIGH7.8GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-10921HIGH7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-10920HIGH7.8GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-64104HIGH7.3LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2025-64103CRITICAL9.8Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has...
CVE-2025-64102CRITICAL9.8Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an ...
CVE-2025-64101HIGH8.8Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability e...
CVE-2025-61876MEDIUM5Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an aut...
CVE-2025-64100MEDIUM6.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,...
CVE-2025-62797HIGH8.6FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vul...
CVE-2025-57227HIGH7.8An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via ...
CVE-2025-35980Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-11232HIGH7.5To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at th...
CVE-2025-62792HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer ...
CVE-2025-62791HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCis...
CVE-2025-62790HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch...
CVE-2025-62789HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now