2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-45513CRITICAL9.8Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.
CVE-2025-28203HIGH8.8Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
CVE-2025-28202HIGH8.8Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services witho...
CVE-2025-28201MEDIUM6.8An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain ...
CVE-2025-28200CRITICAL9.8Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits o...
CVE-2025-45887CRITICAL9.1Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
CVE-2025-45885CRITICAL9.8PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Att...
CVE-2025-4382MEDIUM5.9A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB...
CVE-2025-4206HIGH7.2The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulner...
CVE-2025-3897MEDIUM5.9The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 vi...
CVE-2025-3528HIGH8.2A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has...
CVE-2025-1087CRITICAL9.3Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to exe...
CVE-2025-46392MEDIUM6.5Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Ap...
CVE-2025-4403CRITICAL9.8The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a...
CVE-2025-3949MEDIUM4.3The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...
CVE-2025-4472HIGH7.8A vulnerability was found in code-projects Departmental Store Management System 1.0. It has been classified as critical....
CVE-2025-4471HIGH7.8A vulnerability, which was classified as critical, has been found in code-projects Jewelery Store Management system 1.0....
CVE-2025-4470MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by t...
CVE-2025-4469MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected...
CVE-2025-4468CRITICAL9.8A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This iss...
CVE-2025-4467CRITICAL9.8A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been declared as critical. This ...
CVE-2025-3605CRITICAL9.8The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2025-3455HIGH8.8The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized...
CVE-2025-37889MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Consistently treat platform_max as contr...
CVE-2025-37888MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now