2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-34421HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34420HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34419HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34418HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34417HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34416HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34410HIGH7.11Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functi...
CVE-2025-34395HIGH7.5Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser...
CVE-2025-13155HIGH8.5An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user ...
CVE-2025-13152HIGH7.8A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that co...
CVE-2025-12046HIGH7.8A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a lo...
CVE-2025-8110HIGH8.8Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
CVE-2025-41358HIGH8.3Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne...
CVE-2025-7073HIGH7.8A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privil...
CVE-2025-66675HIGH8.2Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi...
CVE-2025-14390HIGH8.8The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to ...
CVE-2025-1161HIGH7.1Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem a...
CVE-2025-12952HIGH8.7A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e...
CVE-2025-9571HIGH8.7A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa...
CVE-2025-13073HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13072HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13339HIGH7.5The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in...
CVE-2025-67507HIGH8.1Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont...
CVE-2025-67501HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-61813HIGH7.4ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now