CVEs from 2025

12,161 normalized CVEs published or assigned in this year.

Total
12,161
critical
critical 1,301
high
high 1,894
medium
medium 1,908
low
low 193
% Critical
10.7%
% with KEV
1.5%
% with exploit
1.5%

Top products

  • i-educar 80
  • office_long_term_servicing_channel 35
  • office 34
  • best_salon_management_system 33
  • apartment_management_system 30
  • inventory_management_system 28
  • gcp 24
  • online_learning_management_system 21
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2025-34291 high 8.8 10.0 6mo ago Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with al… python
CVE-2025-14174 high 9.5 5mo ago Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability co… redhatdebiansuse
CVE-2025-43529 high 9.5 5mo ago Important: webkit2gtk3 security update rockylinuxredhatsusedebian
CVE-2025-31277 high 9.5 8mo ago Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corru… redhatsusedebian
CVE-2025-41244 high 9.5 8mo ago Important: open-vm-tools security update redhatrockylinuxsusedebian
CVE-2025-38352 high 9.5 9mo ago Important: kernel security update redhatrockylinuxsusedebian
CVE-2025-6558 high 9.5 10mo ago Important: webkit2gtk3 security update redhatrockylinuxdebiansuse
CVE-2025-48384 high 9.5 10mo ago Important: git security update redhatrockylinuxdebiansuse
CVE-2025-27363 high 9.5 1y ago Important: freetype security update redhatrockylinuxarchdebian+1
CVE-2025-24201 high 9.5 1y ago Important: webkit2gtk3 security update redhatrockylinuxdebiansuse
CVE-2025-24813 medium 7.0 1y ago Moderate: tomcat security update redhatrockylinuxsusedebian+1
CVE-2025-68461 unknown 1.5 3mo ago Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. debian