2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57773CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 para...
CVE-2025-57772CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JD...
CVE-2025-57760HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exis...
CVE-2025-53120CRITICAL9.4A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and s...
CVE-2025-50722CRITICAL9.8Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Commo...
CVE-2025-29421HIGH7.5PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
CVE-2025-29420HIGH7.5PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
CVE-2025-9409MEDIUM6.5A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUplo...
CVE-2025-55575CRITICAL9.8SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP ...
CVE-2025-55574MEDIUM6.1Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code
CVE-2025-55409HIGH8.8FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbi...
CVE-2025-55301MEDIUM6.7The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local sto...
CVE-2025-53119HIGH7.5An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to...
CVE-2025-53118CRITICAL9.8An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup f...
CVE-2025-3478HIGH8.5A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulne...
CVE-2025-29523HIGH7.2D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability vi...
CVE-2025-5302HIGH8.6A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifical...
CVE-2025-56216HIGH8.5phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
CVE-2025-56215MEDIUM6.5phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
CVE-2025-56214CRITICAL9.8phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
CVE-2025-56212CRITICAL9.8phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
CVE-2025-53510HIGH8.8A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9...
CVE-2025-53085HIGH8.8A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8...
CVE-2025-52930HIGH8.8A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9...
CVE-2025-52456HIGH8.8A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now