2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61146MEDIUM4saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
CVE-2025-61145MEDIUM5libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
CVE-2025-61144HIGH7.3libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
CVE-2025-61143MEDIUM5.5libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-70058HIGH7.4An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application dis...
CVE-2025-70045HIGH7.4An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application dis...
CVE-2025-70044MEDIUM6.5An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
CVE-2025-70043CRITICAL9.1An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d...
CVE-2025-14905HIGH7.2A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac...
CVE-2025-69700HIGH7.5Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which...
CVE-2025-59873MEDIUM5.9An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s...
CVE-2025-40986MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaS...
CVE-2025-40701MEDIUM5.1Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute J...
CVE-2025-41002CRITICAL9.3SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create...
CVE-2025-14339MEDIUM6.5The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-65995MEDIUM6.5When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat...
CVE-2025-62326MEDIUM4.8HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which wo...
CVE-2025-70833CRITICAL9.4An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u...
CVE-2025-15583MEDIUM5.4A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file uti...
CVE-2025-15582HIGH8.1A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update ...
CVE-2025-70831CRITICAL9.8A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica...
CVE-2025-69410HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69409HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69408HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69407HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now