2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62171HIGH7.5ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick ...
CVE-2025-62168HIGH7.5Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential...
CVE-2025-8414CRITICAL9.4Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the ...
CVE-2025-62356HIGH7.5A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local f...
CVE-2025-62353CRITICAL9.8A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo...
CVE-2025-60279CRITICAL9.6A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users...
CVE-2025-59043HIGH7.5OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects aft...
CVE-2025-58747MEDIUM6.1Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable t...
CVE-2025-57567CRITICAL9.1A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l...
CVE-2025-49655CRITICAL9.8Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc...
CVE-2025-26625HIGH8.6Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re...
CVE-2025-11905HIGH8.8A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the...
CVE-2025-60361LOW3.3radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
CVE-2025-55085HIGH7.5In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsi...
CVE-2025-48087MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlit...
CVE-2025-11904HIGH7.2A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo...
CVE-2025-60360MEDIUM5.5radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
CVE-2025-60359MEDIUM5.5radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
CVE-2025-48044HIGH8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated ...
CVE-2025-11903HIGH7.2A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cm...
CVE-2025-11902HIGH7.2A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findFie...
CVE-2025-11895MEDIUM4.3The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and includ...
CVE-2025-55100CRITICAL9.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55099MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55098MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now