2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-44004HIGH7.2Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance whic...
CVE-2025-44001MEDIUM4Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...
CVE-2025-25229MEDIUM5.4Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privi...
CVE-2025-54063CRITICAL9.6Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one...
CVE-2025-53187CRITICAL9.8Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of th...
CVE-2025-25231HIGH7.5Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga...
CVE-2025-8866MEDIUM5.1YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An un...
CVE-2025-45146CRITICAL9.8ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/...
CVE-2025-38499MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_...
CVE-2025-8865MEDIUM4.1The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when...
CVE-2025-8859HIGH8.8A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionali...
CVE-2025-8864MEDIUM6.8Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup lo...
CVE-2025-8852MEDIUM4.3A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/u...
CVE-2025-8851MEDIUM5.3A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffe...
CVE-2025-8863HIGH7YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
CVE-2025-8862HIGH7YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag config...
CVE-2025-8847MEDIUM5.4A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the...
CVE-2025-8846HIGH7.8A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser....
CVE-2025-8845HIGH7.8A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the fi...
CVE-2025-8672HIGH7.8MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permission...
CVE-2025-8844MEDIUM5.5A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_te...
CVE-2025-8843HIGH7.8A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file ou...
CVE-2025-8842HIGH7.8A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of ...
CVE-2025-8841MEDIUM6.1A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the func...
CVE-2025-8840MEDIUM5.4A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/delete...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now