2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55006HIGH8.8Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image u...
CVE-2025-55003MEDIUM5.7OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-55001MEDIUM6.5OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-55000MEDIUM6.5OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-54999LOW3.7OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-54998MEDIUM5.3OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-54997CRITICAL9.1OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-55152MEDIUM5.3oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and...
CVE-2025-54996HIGH7.2OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-54888HIGH8.7Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4....
CVE-2025-54417HIGH8.8Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a v...
CVE-2025-8744HIGH7.3A vulnerability classified as critical was found in CesiumLab Web up to 4.0. This vulnerability affects unknown code of ...
CVE-2025-6573CRITICAL9.8Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from t...
CVE-2025-46709HIGH7.5Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern...
CVE-2025-8743MEDIUM5.4A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. This affects an unknown part of the...
CVE-2025-8742MEDIUM6.3A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unk...
CVE-2025-8741MEDIUM5.9A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerab...
CVE-2025-8740MEDIUM5.4A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0. It has been classified as problematic. Affected is an unkno...
CVE-2025-8739MEDIUM4.3A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unkno...
CVE-2025-55188LOW3.67-Zip before 25.01 does not always properly handle symbolic links during extraction.
CVE-2025-8738MEDIUM5.5A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnera...
CVE-2025-8737LOW3.5A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affe...
CVE-2025-8736MEDIUM5.3A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the ...
CVE-2025-8735LOW3.3A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the functi...
CVE-2025-4796HIGH8.8The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now