2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40990MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-40989MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-61735HIGH7.3Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5...
CVE-2025-61734HIGH7.5Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's ...
CVE-2025-61733HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin...
CVE-2025-54468MEDIUM4.7A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an ex...
CVE-2025-54292MEDIUM4.6Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attac...
CVE-2025-54291MEDIUM5.3Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo...
CVE-2025-54290MEDIUM5.3Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to d...
CVE-2025-54289HIGH8.1Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions...
CVE-2025-54288MEDIUM6.8Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attack...
CVE-2025-54287MEDIUM6.5Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co...
CVE-2025-54286HIGH8.8Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and s...
CVE-2025-40646MEDIUM5.4Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a...
CVE-2025-40645HIGH8.7Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensiti...
CVE-2025-9697CRITICAL9.8The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a...
CVE-2025-9587HIGH8.6The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before usin...
CVE-2025-61692HIGH7.8VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, ...
CVE-2025-61691HIGH7.8VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted f...
CVE-2025-61690HIGH7.8KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted fil...
CVE-2025-58777HIGH7.8VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specia...
CVE-2025-58776HIGH8.4KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially ...
CVE-2025-58775HIGH8.4KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted...
CVE-2025-11221CRITICAL9.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero...
CVE-2025-11182HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now