2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8110HIGH8.8Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
CVE-2025-41358HIGH8.3Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne...
CVE-2025-7073HIGH7.8A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privil...
CVE-2025-66675HIGH8.2Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi...
CVE-2025-14390HIGH8.8The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to ...
CVE-2025-1161HIGH7.1Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem a...
CVE-2025-12952HIGH8.7A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e...
CVE-2025-9571HIGH8.7A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa...
CVE-2025-13073HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13072HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13339HIGH7.5The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in...
CVE-2025-67507HIGH8.1Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont...
CVE-2025-67501HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-61813HIGH7.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61812HIGH8.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61810HIGH8.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2025-67494HIGH8.6ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f...
CVE-2025-66645HIGH7.5NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App....
CVE-2025-65513HIGH7.5fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to...
CVE-2025-67488HIGH8.8SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce an...
CVE-2025-66626HIGH7.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version...
CVE-2025-64899HIGH7.8Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by...
CVE-2025-64785HIGH7.8Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by...
CVE-2025-13743HIGH7.5Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serializatio...
CVE-2025-66457HIGH8.8Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now