2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46717LOW3.3sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very l...
CVE-2025-46611MEDIUM6.1Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted sc...
CVE-2025-46610HIGH8.8ARTEC EMA Mail 6.92 allows CSRF.
CVE-2025-26846CRITICAL9.8An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to ...
CVE-2025-26841MEDIUM6.1Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code ...
CVE-2025-45835HIGH7.5A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_...
CVE-2025-40627MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr...
CVE-2025-40626MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr...
CVE-2025-47271MEDIUM6.3The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance...
CVE-2025-47270HIGH7.5nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2025-46729LOW2.1julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web the...
CVE-2025-32390HIGH8.5EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Know...
CVE-2025-22247MEDIUM6.1VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a...
CVE-2025-1533HIGH8.2A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu...
CVE-2025-41393MEDIUM6.1Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implem...
CVE-2025-3496HIGH7.5An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluet...
CVE-2025-4561HIGH8.8The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to up...
CVE-2025-4560MEDIUM6.9The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to a...
CVE-2025-4559CRITICAL9.8The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arb...
CVE-2025-3649MEDIUM6.8The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs,...
CVE-2025-3597MEDIUM5.9The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executi...
CVE-2025-4558CRITICAL9.8The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to...
CVE-2025-4557CRITICAL9.1The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthe...
CVE-2025-4556CRITICAL9.8The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerabilit...
CVE-2025-4555CRITICAL9.8The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now