2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43860HIGH7.6OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-...
CVE-2025-32967MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. A logging overs...
CVE-2025-32794HIGH7.6OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-...
CVE-2025-24917HIGH7.8In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could ...
CVE-2025-24916HIGH7.8When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions pr...
CVE-2025-5114CRITICAL9.1A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affect...
CVE-2025-5112CRITICAL9.8A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o...
CVE-2025-5111CRITICAL9.8A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is...
CVE-2025-5110CRITICAL9.8A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno...
CVE-2025-3580MEDIUM5.5An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently dele...
CVE-2025-5109CRITICAL9.8A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th...
CVE-2025-5108CRITICAL9.8A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Uplo...
CVE-2025-5107CRITICAL9.8A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown co...
CVE-2025-48292HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48289CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issu...
CVE-2025-48287CRITICAL9.8Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Inject...
CVE-2025-48286HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restau...
CVE-2025-48283CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support M...
CVE-2025-48275MEDIUM6.5Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Ac...
CVE-2025-48273HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Porta...
CVE-2025-48271MEDIUM6.5Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-48245HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick C...
CVE-2025-48241HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verg...
CVE-2025-47690HIGH8.8Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allow...
CVE-2025-47687CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now