2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49842LOW1conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.2...
CVE-2025-0320HIGH7.8Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Win...
CVE-2025-6020HIGH7.8A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, ...
CVE-2025-5777HIGH7.5Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual serv...
CVE-2025-5349HIGH8.8Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
CVE-2025-4365HIGH7.5Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
CVE-2025-5700MEDIUM6.4The Simple Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all...
CVE-2025-5291MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2025-3880MEDIUM4.3The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-6050MEDIUM4.8Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin inter...
CVE-2025-3515CRITICAL9.8The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads d...
CVE-2025-40674MEDIUM5.1Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code ...
CVE-2025-6173HIGH7.2A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown f...
CVE-2025-6167CRITICAL9.8A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function ...
CVE-2025-6166MEDIUM5.1A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the func...
CVE-2025-6165HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability aff...
CVE-2025-6164HIGH8.8A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an u...
CVE-2025-5209MEDIUM4.8The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow hi...
CVE-2025-6163HIGH8.8A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is...
CVE-2025-6162HIGH8.8A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this v...
CVE-2025-6161CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected...
CVE-2025-6160CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1....
CVE-2025-6159CRITICAL9.8A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affec...
CVE-2025-6158HIGH8.8A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the ...
CVE-2025-3494Rejected reason: This CVE ID has been rejected by its CNA as it was not a security issue.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now