2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68613HIGH8.8n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1....
CVE-2025-68481HIGH8.8FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to ve...
CVE-2025-14966HIGH7.2A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic...
CVE-2025-68478HIGH7.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p...
CVE-2025-14958HIGH7.8A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability a...
CVE-2025-58052HIGH8.1Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to ...
CVE-2025-14956HIGH7.1A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReade...
CVE-2025-14812HIGH7.5ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being sh...
CVE-2025-14809HIGH7.4ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content bein...
CVE-2025-67442HIGH7.6EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export...
CVE-2025-66905HIGH7.5The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them ...
CVE-2025-66909HIGH7.5Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerabilit...
CVE-2025-50681HIGH7.5igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft...
CVE-2025-1927HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al...
CVE-2025-14847HIGH8.7Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe...
CVE-2025-66524HIGH8.8Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di...
CVE-2025-14151HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par...
CVE-2025-66499HIGH7.8A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft...
CVE-2025-66498HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66497HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66496HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66495HIGH7.8A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1...
CVE-2025-66494HIGH7.8A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on...
CVE-2025-66493HIGH7.8A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,...
CVE-2025-13999HIGH7.2The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now