2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-34179HIGH8.7NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gatew...
CVE-2025-14383HIGH7.5The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param...
CVE-2025-65781HIGH8.2An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upl...
CVE-2025-65780HIGH8.8An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated ...
CVE-2025-65779HIGH7.5An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticate...
CVE-2025-65778HIGH8.1An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attac...
CVE-2025-37731HIGH7.4Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica...
CVE-2025-14708HIGH7.5A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit...
CVE-2025-14712HIGH8.7Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil...
CVE-2025-14549HIGH8.1In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR ...
CVE-2025-13355HIGH7.1The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t...
CVE-2025-12684HIGH7.1The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t...
CVE-2025-67900HIGH8.1NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
CVE-2025-14656HIGH8.8A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedW...
CVE-2025-14655HIGH8.8A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer o...
CVE-2025-14654HIGH8.8A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of th...
CVE-2025-14648HIGH7.2A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown function...
CVE-2025-13126HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame...
CVE-2025-14642HIGH7.2A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the f...
CVE-2025-14641HIGH7.2A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the...
CVE-2025-14589HIGH8.8A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing...
CVE-2025-14542HIGH7.5The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp...
CVE-2025-14476HIGH8.8The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2025-14475HIGH8.1The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2025-14397HIGH8.8The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now