2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-14068HIGH7.5The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions...
CVE-2025-12570HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2025-67725HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously...
CVE-2025-67508HIGH8.4gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh...
CVE-2025-14044HIGH8.1The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2025-13334HIGH8.1The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi...
CVE-2025-12968HIGH8.8The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and...
CVE-2025-12824HIGH8.8The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ...
CVE-2025-13886HIGH7.5The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ...
CVE-2025-10451HIGH8.2Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
CVE-2025-67779HIGH7.5It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den...
CVE-2025-66446HIGH7.5MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow...
CVE-2025-34506HIGH8.8WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator...
CVE-2025-66586HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp...
CVE-2025-66585HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup...
CVE-2025-66429HIGH8.8An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow...
CVE-2025-55184HIGH7.5A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1...
CVE-2025-36936HIGH7.8In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. Thi...
CVE-2025-36935HIGH7.8In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This ...
CVE-2025-36934HIGH7.4In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co...
CVE-2025-36932HIGH7.8In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp...
CVE-2025-36931HIGH7.8In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea...
CVE-2025-36930HIGH7.8In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea...
CVE-2025-36928HIGH7.8In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could ...
CVE-2025-36927HIGH7.8In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now