2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60357HIGH8.1AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv...
CVE-2025-45870MEDIUM6.5LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c...
CVE-2025-45868HIGH8.8LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo...
CVE-2025-71388HIGH7.6stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ...
CVE-2025-71377HIGH8.7stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me...
CVE-2025-65720CRITICAL9.8An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user...
CVE-2025-32781MEDIUM6.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior...
CVE-2025-56365HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co...
CVE-2025-56364HIGH7.5A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin...
CVE-2025-56363HIGH7.5A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi...
CVE-2025-56362HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev...
CVE-2025-56361HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev...
CVE-2025-62826MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-62675MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-53379HIGH7.5A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio...
CVE-2025-43892MEDIUM4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v...
CVE-2025-11698CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit...
CVE-2025-12012CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u...
CVE-2025-12011CRITICAL9.2A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to ...
CVE-2025-40945HIGH8.5A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),...
CVE-2025-8412LOW2A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa...
CVE-2025-15665MEDIUM5.4The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl...
CVE-2025-45869HIGH7.3LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti...
CVE-2025-6784HIGH8.8The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ...
CVE-2025-5017MEDIUM4.9The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now