2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5074CRITICAL9.8A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown functio...
CVE-2025-5073CRITICAL9.8A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some u...
CVE-2025-41403HIGH8.3Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching ...
CVE-2025-3836HIGH8.3Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon ev...
CVE-2025-3444MEDIUM6.5Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated L...
CVE-2025-4419MEDIUM4.3The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 vi...
CVE-2025-4405MEDIUM5.4The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all v...
CVE-2025-4280MEDIUM4.8MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissi...
CVE-2025-4123MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire...
CVE-2025-4133MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts whe...
CVE-2025-5062MEDIUM6.1The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' p...
CVE-2025-3887HIGH8.8GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-3885MEDIUM6.5Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows netwo...
CVE-2025-3884HIGH7.5Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac...
CVE-2025-3883HIGH8.8eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw...
CVE-2025-3882HIGH8.8eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-3881HIGH8.8eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all...
CVE-2025-3486HIGH8.8Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac...
CVE-2025-3484CRITICAL9.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-3483HIGH7.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-3482HIGH7.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-3481HIGH7.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-3480MEDIUM6.5MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability...
CVE-2025-2759HIGH7.8GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta...
CVE-2025-5059HIGH7.2A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now