2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46599MEDIUM6.8CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that,...
CVE-2025-3775MEDIUM6.5The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2025-3752MEDIUM6.4The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-46595MEDIUM6.4An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to ...
CVE-2025-46547MEDIUM6.1In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an a...
CVE-2025-46546HIGH8.8In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This ...
CVE-2025-46545MEDIUM4.8In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an adm...
CVE-2025-46544MEDIUM6.5In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.
CVE-2025-43865HIGH8.2React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-re...
CVE-2025-43864HIGH7.5React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an app...
CVE-2025-3606HIGH8.7Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing s...
CVE-2025-2185HIGH8.5ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient se...
CVE-2025-46275CRITICAL9.8WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator accou...
CVE-2025-46274CRITICAL9.8UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create en...
CVE-2025-46273CRITICAL9.8UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges...
CVE-2025-46272CRITICAL9.3WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke...
CVE-2025-46271CRITICAL9.3UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu...
CVE-2025-3749MEDIUM6.4The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all...
CVE-2025-1294HIGH7.2The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up ...
CVE-2025-43861MEDIUM5.4ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to...
CVE-2025-29529MEDIUM6.5ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via th...
CVE-2025-25777HIGH8Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user p...
CVE-2025-26382CRITICAL9.3Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
CVE-2025-43859CRITICAL9.1h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in ...
CVE-2025-43858CRITICAL9.2YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now