2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55733CRITICAL9.6DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r...
CVE-2025-55306CRITICAL9.8GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F...
CVE-2025-55303MEDIUM6.1Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimiza...
CVE-2025-52338MEDIUM5.3An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows...
CVE-2025-50891HIGH7.2The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary ...
CVE-2025-43745MEDIUM6.5A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 t...
CVE-2025-43737MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through ...
CVE-2025-33008MEDIUM5.4IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vu...
CVE-2025-31988MEDIUM4.8HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
CVE-2025-9151MEDIUM6.3A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct...
CVE-2025-9150HIGH7.3A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affec...
CVE-2025-9149CRITICAL9.8A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg...
CVE-2025-8450HIGH8.2Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload ...
CVE-2025-55295MEDIUM6.5qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e...
CVE-2025-55294CRITICAL9.8screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue....
CVE-2025-55153Rejected reason: This CVE is a duplicate of another CVE.
CVE-2025-9148MEDIUM6.3A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/se...
CVE-2025-9147MEDIUM6.1A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted el...
CVE-2025-54881MEDIUM5.3Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2025-54880MEDIUM6.1Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2025-54411MEDIUM5.4Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable t...
CVE-2025-52478MEDIUM5.4n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability w...
CVE-2025-51506MEDIUM6.5In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKe...
CVE-2025-38615MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: cancle set bad inode after removing name ...
CVE-2025-38614MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure tha...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now