2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47436CRITICAL9.8Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompre...
CVE-2025-3600HIGH7.5In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may...
CVE-2025-22756Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-47445CRITICAL9.8Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Ev...
CVE-2025-3931HIGH7.8A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's ...
CVE-2025-3769MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
CVE-2025-4430HIGH8.6Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in ve...
CVE-2025-47292CRITICAL9.5Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175b...
CVE-2025-3834HIGH8.1Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU Histo...
CVE-2025-3833HIGH8.1Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MF...
CVE-2025-26864HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili...
CVE-2025-26795HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili...
CVE-2025-2875HIGH8.7CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of...
CVE-2025-0020Rejected reason: “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it i...
CVE-2025-47899Rejected reason: Not used
CVE-2025-47898Rejected reason: Not used
CVE-2025-47897Rejected reason: Not used
CVE-2025-47896Rejected reason: Not used
CVE-2025-47895Rejected reason: Not used
CVE-2025-47894Rejected reason: Not used
CVE-2025-47893Rejected reason: Not used
CVE-2025-47892Rejected reason: Not used
CVE-2025-47891Rejected reason: Not used
CVE-2025-4520MEDIUM4.3The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2025-3623CRITICAL9.1The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now