Skip to main content

Year archive

CVEs published in 2025

Archive summary

48,163 CVEs published in 2025 — 4,093 Critical, 16,161 High, 23,604 Medium, 3,395 Low, 910 Unrated.

CVE-2024-56332

Published Jan 3, 2025

Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Den…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56412

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56411

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56410

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in cus…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36613

Published Jan 3, 2025

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or o…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35365

Published Jan 3, 2025

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21610

Published Jan 3, 2025

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the li…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-21609

Published Jan 3, 2025

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-56514

Published Jan 3, 2025

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karma…

CVSS 5.3 · Medium

CVE-2024-56513

Published Jan 3, 2025

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode…

CVSS 8.7 · High

CVE-2024-56409

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site sc…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56366

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site sc…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56365

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site sc…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56408

Published Jan 3, 2025

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspre…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56324

Published Jan 3, 2025

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-56322

Published Jan 3, 2025

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) fe…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-56321

Published Jan 3, 2025

GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potent…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-56320

Published Jan 3, 2025

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-55078

Published Jan 3, 2025

An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS 9.8 · Critical

CVE-2024-48814

Published Jan 3, 2025

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 47,876-47,900 of 48,163 CVEsPage 1916 of 1927