2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10608HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file ...
CVE-2025-59342MEDIUM5.5esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw ...
CVE-2025-59341HIGH7.7esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion...
CVE-2025-59339MEDIUM4.4The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording tt...
CVE-2025-58767MEDIUM5.3REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing...
CVE-2025-58766CRITICAL9Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and ear...
CVE-2025-58432HIGH7.8ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all ...
CVE-2025-58431MEDIUM6.2ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earl...
CVE-2025-10607MEDIUM6.5A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil...
CVE-2025-10606MEDIUM6.1A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file...
CVE-2025-10605MEDIUM6.1A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the fi...
CVE-2025-10604CRITICAL9.8A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admi...
CVE-2025-59304CRITICAL9.8A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote...
CVE-2025-35436HIGH7.5CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote...
CVE-2025-35435MEDIUM5.3CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could caus...
CVE-2025-35434CRITICAL9.8CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces...
CVE-2025-35433HIGH8.8CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a ...
CVE-2025-35432HIGH7.5CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker...
CVE-2025-35431MEDIUM5.4CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L...
CVE-2025-35430MEDIUM6.5CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'...
CVE-2025-10603CRITICAL9.8A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functio...
CVE-2025-10602HIGH8.8A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknow...
CVE-2025-10601CRITICAL9.8A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the...
CVE-2025-10600CRITICAL9.8A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r...
CVE-2025-10599CRITICAL9.8A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now