2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62508MEDIUM6.5Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulne...
CVE-2025-11914HIGH7.5A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function ...
CVE-2025-62511MEDIUM6.3yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 ...
CVE-2025-11925MEDIUM6.1Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially all...
CVE-2025-11913MEDIUM6.5A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is ...
CVE-2025-11912HIGH8.8A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file ...
CVE-2025-11911HIGH8.8A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t...
CVE-2025-11910HIGH8.8A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct...
CVE-2025-62505LOW3LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-...
CVE-2025-56320MEDIUM5.4CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its cha...
CVE-2025-56316CRITICAL9.8A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo...
CVE-2025-56221CRITICAL9.8A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut...
CVE-2025-56218CRITICAL9.8An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c...
CVE-2025-34282CRITICAL9.1ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload ...
CVE-2025-34281MEDIUM5.4ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Galle...
CVE-2025-11909HIGH8.8A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi...
CVE-2025-11908HIGH8.8A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f...
CVE-2025-62430MEDIUM5.4ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site ...
CVE-2025-62424MEDIUM6.5ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/templa...
CVE-2025-62422HIGH8.8DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datas...
CVE-2025-62421MEDIUM5.4DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scrip...
CVE-2025-62420HIGH8.8DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vuln...
CVE-2025-62419HIGH7.5DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vuln...
CVE-2025-60514MEDIUM6.5Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.
CVE-2025-57164MEDIUM6.5Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now