2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41229HIGH8.2VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 ...
CVE-2025-40635CRITICAL9.3SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to...
CVE-2025-30193HIGH7.5In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP conn...
CVE-2025-40634CRITICAL9.2Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 rout...
CVE-2025-40633MEDIUM5.1A Stored Cross-Site Scripting (XSS) vulnerability has been found in Koibox for versions prior to e8cbce2. This vulnerab...
CVE-2025-37892HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob(...
CVE-2025-4951MEDIUM4.6Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in ...
CVE-2025-4322CRITICAL9.8The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc...
CVE-2025-2929HIGH7.1The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-4971HIGH8.5Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execu...
CVE-2025-3079HIGH8.7A passback vulnerability which relates to office/small office multifunction printers and laser printers.
CVE-2025-3078HIGH8.7A passback vulnerability which relates to production printers and office multifunction printers.
CVE-2025-1308HIGH8.4A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.
CVE-2025-48340CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privile...
CVE-2025-3223MEDIUM5.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST...
CVE-2025-47949HIGH7.5samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to ver...
CVE-2025-47946MEDIUM6.1Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25....
CVE-2025-47944HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1...
CVE-2025-47935HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource ...
CVE-2025-46441MEDIUM5.3Path Traversal: '.../...//' vulnerability in ctltwp Section Widget section-widget allows Path Traversal.This issue affec...
CVE-2025-39402CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web...
CVE-2025-39401CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web...
CVE-2025-39395CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apa...
CVE-2025-39393HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital ...
CVE-2025-39392HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now