2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40655CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40654CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-5743HIGH7CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-5742MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a...
CVE-2025-5741MEDIUM6.9CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-5740HIGH8.6CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-4681HIGH8.6Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abu...
CVE-2025-4680HIGH8.6Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorr...
CVE-2025-3905MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact...
CVE-2025-3899MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Cer...
CVE-2025-3898HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou...
CVE-2025-3117MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact...
CVE-2025-3116HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou...
CVE-2025-3112HIGH7.1CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated...
CVE-2025-5945Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-27819HIGH7.5In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Co...
CVE-2025-27818HIGH8.8A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the clus...
CVE-2025-27817HIGH7.5A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients a...
CVE-2025-4954HIGH8.8The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenti...
CVE-2025-4840HIGH7.5The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter b...
CVE-2025-1041CRITICAL9.8An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v...
CVE-2025-5952HIGH7.3A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the f...
CVE-2025-5935HIGH7.5A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is...
CVE-2025-3076MEDIUM5.4The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text...
CVE-2025-5934HIGH8.8A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now