2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61952 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-58427 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-47873 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-13406 | MEDIUM | 6.8 | 0.3% | Mar 17, 2026 | NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows ... |
| CVE-2025-62320 | MEDIUM | 6.1 | 0.2% | Mar 17, 2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s... |
| CVE-2025-31966 | LOW | 2.7 | 0.2% | Mar 17, 2026 | HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th... |
| CVE-2025-71239 | MEDIUM | 5.5 | 0.1% | Mar 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class ... |
| CVE-2025-69902 | CRITICAL | 9.8 | 2.1% | Mar 16, 2026 | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e... |
| CVE-2025-50881 | HIGH | 8.8 | 0.7% | Mar 16, 2026 | The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Ex... |
| CVE-2025-69693 | MEDIUM | 5.4 | 0.3% | Mar 16, 2026 | Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) va... |
| CVE-2025-68971 | MEDIUM | 6.5 | 0.5% | Mar 16, 2026 | In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach... |
| CVE-2025-69809 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values t... |
| CVE-2025-69808 | CRITICAL | 9.1 | 0.3% | Mar 16, 2026 | An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive... |
| CVE-2025-69727 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (... |
| CVE-2025-69196 | MEDIUM | 6.5 | 0.4% | Mar 16, 2026 | FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r... |
| CVE-2025-69768 | HIGH | 7.5 | 0.4% | Mar 16, 2026 | SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the... |
| CVE-2025-66687 | HIGH | 7.5 | 0.7% | Mar 16, 2026 | Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of ... |
| CVE-2025-65734 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, ... |
| CVE-2025-54758 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2025-53815 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2025-53517 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2025-69784 | HIGH | 8.8 | 0.2% | Mar 16, 2026 | A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to ... |
| CVE-2025-69783 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust... |
| CVE-2025-62319 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool... |
| CVE-2025-57543 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitra... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now