2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65730HIGH8.8Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for sig...
CVE-2025-64053HIGH7.5A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentia...
CVE-2025-14092HIGH7.2A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of ...
CVE-2025-14091HIGH7.3A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555. This vul...
CVE-2025-14090HIGH7.2A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the fi...
CVE-2025-64057HIGH8.3Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to sto...
CVE-2025-58098HIGH8.3Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the ...
CVE-2025-14086HIGH8.8A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1...
CVE-2025-14085HIGH8.8A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-...
CVE-2025-13654HIGH7.5A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a conditio...
CVE-2025-59775HIGH7.5Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and M...
CVE-2025-55753HIGH7.5An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in defaul...
CVE-2025-13614HIGH8.1The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' s...
CVE-2025-12879HIGH8.8The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i...
CVE-2025-12851HIGH8.1The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,...
CVE-2025-12850HIGH7.5The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versio...
CVE-2025-12189HIGH8.8The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPres...
CVE-2025-12181HIGH8.8The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-12154HIGH8.8The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2025-12153HIGH8.8The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-13066HIGH8.8The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,...
CVE-2025-66564HIGH7.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest...
CVE-2025-66559HIGH8Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising it...
CVE-2025-14051HIGH8.8A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddres...
CVE-2025-13373HIGH8.7Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could al...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now