2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5329CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software ...
CVE-2025-15368HIGH8.8The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 ...
CVE-2025-14740MEDIUM6.7Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling...
CVE-2025-59818CRITICAL9.8This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file ...
CVE-2025-41085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not p...
CVE-2025-15508MEDIUM5.3The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2025-15507MEDIUM5.3The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-15487MEDIUM4.9The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t...
CVE-2025-15482MEDIUM5.3The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2025-15285HIGH7.5The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2025-15268HIGH7.5The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API ...
CVE-2025-15260MEDIUM6.5The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i...
CVE-2025-14461MEDIUM5.3The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a...
CVE-2025-29867HIGH8.5Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Hancom Inc. Hancom Office 2018, Hancom In...
CVE-2025-69621HIGH8.1An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to ov...
CVE-2025-69620MEDIUM5A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the in...
CVE-2025-36094HIGH8.1IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and ...
CVE-2025-36033MEDIUM5.4IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 th...
CVE-2025-33081MEDIUM5.5IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user...
CVE-2025-65081MEDIUM6.9An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This v...
CVE-2025-65080MEDIUM6.9A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulner...
CVE-2025-65079MEDIUM6.9A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices....
CVE-2025-65078CRITICAL9.3An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark device...
CVE-2025-65077HIGH8.8A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devic...
CVE-2025-64438HIGH7.5Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now