2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53417CRITICAL9.3DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
CVE-2025-8539MEDIUM4.8A vulnerability was found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this issue is some unkn...
CVE-2025-8538MEDIUM4.8A vulnerability has been found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this vulnerability...
CVE-2025-8537MEDIUM5.9A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the fun...
CVE-2025-8535CRITICAL9A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects...
CVE-2025-54871HIGH7.8Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app...
CVE-2025-54870HIGH8.7VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules ...
CVE-2025-54865CRITICAL9.8Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missin...
CVE-2025-54804MEDIUM6.5Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH ...
CVE-2025-54803HIGH7.5js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype ...
CVE-2025-54802CRITICAL9.8pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there i...
CVE-2025-54795CRITICAL9.8Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass...
CVE-2025-54794CRITICAL9.1Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead o...
CVE-2025-54780HIGH7.7The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2...
CVE-2025-54387CRITICAL9.8IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 throu...
CVE-2025-54135CRITICAL9.8Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in...
CVE-2025-54130CRITICAL9.8Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in...
CVE-2025-54119CRITICAL10ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versi...
CVE-2025-53544HIGH7.5Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person...
CVE-2025-52892MEDIUM6.5EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP...
CVE-2025-8534LOW2.5A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2pag...
CVE-2025-54797Rejected reason: This CVE is a duplicate of CVE-2025-52464.
CVE-2025-8530HIGH7.5A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue...
CVE-2025-8529MEDIUM6.3A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerabi...
CVE-2025-46094LOW3.8LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actions...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now