2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8136HIGH7.5A vulnerability, which was classified as critical, was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected is an unkn...
CVE-2025-8135HIGH8.8A vulnerability, which was classified as critical, has been found in itsourcecode Insurance Management System 1.0. This ...
CVE-2025-5835HIGH8.8The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability...
CVE-2025-5831HIGH8.8The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_g...
CVE-2025-8134HIGH8.8A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability a...
CVE-2025-8133MEDIUM6.3A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function get...
CVE-2025-7022MEDIUM6.1The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-8132MEDIUM5.4A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is ...
CVE-2025-8131HIGH8.8A vulnerability was found in Tenda AC20 16.03.08.05. It has been declared as critical. Affected by this vulnerability is...
CVE-2025-8129MEDIUM6.1A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back ...
CVE-2025-8128MEDIUM6.3A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de4...
CVE-2025-8127HIGH8.8A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown cod...
CVE-2025-54568LOW3.7Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate...
CVE-2025-8126HIGH8.8A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of t...
CVE-2025-54567MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
CVE-2025-54566MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
CVE-2025-8125CRITICAL9.8A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some...
CVE-2025-54558MEDIUM4.1OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search...
CVE-2025-0253LOW2.4HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configu...
CVE-2025-0252MEDIUM4.8HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate pro...
CVE-2025-0251MEDIUM5.7HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the ...
CVE-2025-8124HIGH8.8A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerabil...
CVE-2025-7742HIGH8.3An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to...
CVE-2025-0250MEDIUM4.9HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authori...
CVE-2025-0249MEDIUM5.9HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now