2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64735HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-64733HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-64301HIGH7.8An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF...
CVE-2025-62500HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-62403HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-61979HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-61952HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-58427HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-47873HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2025-13406MEDIUM6.8NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows ...
CVE-2025-62320MEDIUM6.1HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s...
CVE-2025-31966LOW2.7HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th...
CVE-2025-71239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class ...
CVE-2025-69902CRITICAL9.8A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e...
CVE-2025-50881HIGH8.8The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Ex...
CVE-2025-69693MEDIUM5.4Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) va...
CVE-2025-68971MEDIUM6.5In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach...
CVE-2025-69809CRITICAL9.8A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values t...
CVE-2025-69808CRITICAL9.1An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive...
CVE-2025-69727MEDIUM5.3An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (...
CVE-2025-69196MEDIUM6.5FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r...
CVE-2025-69768HIGH7.5SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the...
CVE-2025-66687HIGH7.5Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of ...
CVE-2025-65734MEDIUM5.4An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, ...
CVE-2025-54758——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now