2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61952HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-58427HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-47873HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-13406MEDIUM6.8NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows ...
CVE-2025-62320MEDIUM6.1HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s...
CVE-2025-31966LOW2.7HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th...
CVE-2025-71239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class ...
CVE-2025-69902CRITICAL9.8A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e...
CVE-2025-50881HIGH8.8The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Ex...
CVE-2025-69693MEDIUM5.4Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) va...
CVE-2025-68971MEDIUM6.5In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach...
CVE-2025-69809CRITICAL9.8A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values t...
CVE-2025-69808CRITICAL9.1An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive...
CVE-2025-69727MEDIUM5.3An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (...
CVE-2025-69196MEDIUM6.5FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r...
CVE-2025-69768HIGH7.5SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the...
CVE-2025-66687HIGH7.5Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of ...
CVE-2025-65734MEDIUM5.4An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, ...
CVE-2025-54758Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-53815Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-53517Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-69784HIGH8.8A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to ...
CVE-2025-69783HIGH7.8A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust...
CVE-2025-62319CRITICAL9.8Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool...
CVE-2025-57543MEDIUM6.1Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitra...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now