2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69653MEDIUM6.5A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb...
CVE-2025-69652MEDIUM6.2GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b...
CVE-2025-69650HIGH7.5GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed ...
CVE-2025-69649HIGH7.5GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary wi...
CVE-2025-69651MEDIUM5.5GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ...
CVE-2025-69646MEDIUM5.5Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_...
CVE-2025-69645MEDIUM5.5Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug ...
CVE-2025-69644MEDIUM5An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing ...
CVE-2025-70363HIGH7.5Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated ...
CVE-2025-15602HIGH8.8Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently...
CVE-2025-59544MEDIUM4.3Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category...
CVE-2025-59543CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab...
CVE-2025-59542CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab...
CVE-2025-59541HIGH8.1Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability all...
CVE-2025-59540MEDIUM5.4Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that...
CVE-2025-55289CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V...
CVE-2025-30413MEDIUM4.4Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber...
CVE-2025-11792HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2025-11791HIGH7.1Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are a...
CVE-2025-11790MEDIUM4.4Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber...
CVE-2025-70995HIGH8.8An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code executi...
CVE-2025-70949HIGH7.5An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a t...
CVE-2025-70948CRITICAL9.3A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain ...
CVE-2025-70614HIGH8.1OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web...
CVE-2025-55208CRITICAL9Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now