2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-14300HIGH8.1The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attack...
CVE-2025-68613HIGH8.8n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1....
CVE-2025-68481HIGH8.8FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to ve...
CVE-2025-14966HIGH7.2A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic...
CVE-2025-68478HIGH7.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p...
CVE-2025-14958HIGH7.8A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability a...
CVE-2025-58052HIGH8.1Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to ...
CVE-2025-14956HIGH7.1A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReade...
CVE-2025-14812HIGH7.5ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being sh...
CVE-2025-14809HIGH7.4ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content bein...
CVE-2025-67442HIGH7.6EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export...
CVE-2025-66905HIGH7.5The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them ...
CVE-2025-66909HIGH7.5Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerabilit...
CVE-2025-50681HIGH7.5igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft...
CVE-2025-1927HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al...
CVE-2025-14847HIGH8.7Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe...
CVE-2025-66524HIGH8.8Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di...
CVE-2025-14151HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par...
CVE-2025-66499HIGH7.8A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft...
CVE-2025-66498HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66497HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66496HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66495HIGH7.8A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1...
CVE-2025-66494HIGH7.8A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on...
CVE-2025-66493HIGH7.8A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now