2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-14134HIGH8.8A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-14133HIGH8.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-14126HIGH8.8A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the c...
CVE-2025-13065HIGH8.8The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, ...
CVE-2025-12966HIGH8.8The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2025-12499HIGH7.2The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content...
CVE-2025-13377HIGH8.1The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbit...
CVE-2025-13292HIGH7.6A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data...
CVE-2025-12510HIGH7.2The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, ...
CVE-2025-34291HIGH8.8Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote cod...
CVE-2025-14111HIGH8.1A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa...
CVE-2025-14108HIGH8.8A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.O...
CVE-2025-14107HIGH8.8A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function ...
CVE-2025-14106HIGH8.8A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of th...
CVE-2025-13426HIGH8.7A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/ja...
CVE-2025-66624HIGH7.5BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat...
CVE-2025-66623HIGH7.4Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F...
CVE-2025-46603HIGH7.5Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentic...
CVE-2025-66566HIGH8.2yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor...
CVE-2025-66471HIGH7.5urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API...
CVE-2025-65879HIGH8.1Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods ...
CVE-2025-65878HIGH7.5The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImage...
CVE-2025-65036HIGH8.3XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.2...
CVE-2025-66418HIGH7.5urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of li...
CVE-2025-65897HIGH8.8zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insuf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now