2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5262HIGH7.5A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder ...
CVE-2025-5244HIGH7.8A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the funct...
CVE-2025-5117HIGH8.8The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of ...
CVE-2025-4412MEDIUM4.8On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it ...
CVE-2025-41653HIGH7.5An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionalit...
CVE-2025-41652CRITICAL9.8The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated r...
CVE-2025-41651CRITICAL9.8Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbit...
CVE-2025-41650HIGH7.5An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt...
CVE-2025-41649HIGH7.5An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer...
CVE-2025-2407CRITICAL9.3Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted acc...
CVE-2025-23393MEDIUM5.6A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in  spacewalk-java allows ...
CVE-2025-5232HIGH7.2A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1...
CVE-2025-5231CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability...
CVE-2025-48382MEDIUM5.5Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fes...
CVE-2025-48054MEDIUM6.8Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnera...
CVE-2025-5230CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unkn...
CVE-2025-5229CRITICAL9.8A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by...
CVE-2025-5228HIGH8.8A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function...
CVE-2025-5227HIGH7.3A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown proces...
CVE-2025-48828HIGH8.1Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t...
CVE-2025-48827CRITICAL9.8vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' ...
CVE-2025-48794Rejected reason: Not used
CVE-2025-48793Rejected reason: Not used
CVE-2025-48792Rejected reason: Not used
CVE-2025-48791Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now