2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62708HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability...
CVE-2025-62707HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability...
CVE-2025-62706MEDIUM6.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF...
CVE-2025-62705MEDIUM4.9OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not ...
CVE-2025-62617HIGH7.2Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit...
CVE-2025-62614HIGH8.7BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an...
CVE-2025-62613MEDIUM6.9VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to b...
CVE-2025-62612MEDIUM5.3FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link i...
CVE-2025-62611HIGH8.2aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings ...
CVE-2025-62610HIGH8.1Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4...
CVE-2025-62513HIGH7.5OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe...
CVE-2025-62247MEDIUM6.5Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 20...
CVE-2025-62248MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Porta...
CVE-2025-58712MEDIUM6.4A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file...
CVE-2025-60343HIGH7.5Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial ...
CVE-2025-60342HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. ...
CVE-2025-60341HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set...
CVE-2025-60340HIGH7.5Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial o...
CVE-2025-60339HIGH7.5Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to ca...
CVE-2025-60337HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan fun...
CVE-2025-60336HIGH7.5A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to caus...
CVE-2025-24934MEDIUM5.4Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. ...
CVE-2025-22178MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22177MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22176MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now