2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40553CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ...
CVE-2025-40552CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would ...
CVE-2025-40551CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ...
CVE-2025-40537HIGH7.5SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat...
CVE-2025-40536CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could...
CVE-2025-9082MEDIUM6.4The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa...
CVE-2025-14039MEDIUM6.4The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na...
CVE-2025-12709MEDIUM6.4The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-8072MEDIUM6.4The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img...
CVE-2025-14610HIGH7.2The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a...
CVE-2025-13471MEDIUM5.3The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin...
CVE-2025-67645HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-55292HIGH8.2Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by t...
CVE-2025-54373MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-21589CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a...
CVE-2025-14988CRITICAL10A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co...
CVE-2025-12810MEDIUM6.5Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a...
CVE-2025-33234HIGH7.8NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulner...
CVE-2025-14911HIGH7.1User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overf...
CVE-2025-69564CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres...
CVE-2025-69563CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete...
CVE-2025-69562CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para...
CVE-2025-69559CRITICAL9.8code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
CVE-2025-65264MEDIUM5.5The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface...
CVE-2025-69565CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now