2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47420HIGH8.7266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.2153...
CVE-2025-0853HIGH7.5The PGS Core plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'save_header_builder' ...
CVE-2025-47419CRITICAL10Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. ...
CVE-2025-47418MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi...
CVE-2025-46573HIGH8.6passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ...
CVE-2025-46572CRITICAL9.3passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ...
CVE-2025-44899CRITICAL9.8There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the we...
CVE-2025-44073CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2025-0649HIGH7.5Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbound...
CVE-2025-47417MEDIUM5.1Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi...
CVE-2025-47256MEDIUM5.6Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha form...
CVE-2025-46820HIGH7.1phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom wo...
CVE-2025-46816CRITICAL9.4goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a...
CVE-2025-4388MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-46815HIGH8The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API...
CVE-2025-44900MEDIUM6.5In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the m...
CVE-2025-37730MEDIUM6.5Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mod...
CVE-2025-25014CRITICAL9.8A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine lea...
CVE-2025-4041CRITICAL9.3In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh serve...
CVE-2025-46736MEDIUM5.3Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal...
CVE-2025-46735LOW1.1Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue ...
CVE-2025-45250MEDIUM5.5MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/u...
CVE-2025-32022MEDIUM4.6Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot whi...
CVE-2025-30165HIGH8vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, ...
CVE-2025-26262MEDIUM6.5An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now