2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59697HIGH7.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-13876HIGH7.8A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is ...
CVE-2025-41015HIGH7.5User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ...
CVE-2025-41014HIGH7.5User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ...
CVE-2025-13295HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message ...
CVE-2025-12465HIGH8.6A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high...
CVE-2025-11789HIGH7.5Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parame...
CVE-2025-11787HIGH8.8Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()',...
CVE-2025-11781HIGH7.8Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded...
CVE-2025-13871HIGH8.8Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to ...
CVE-2025-13724HIGH7.5The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the...
CVE-2025-13534HIGH8.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al...
CVE-2025-13516HIGH8.1The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type...
CVE-2025-10971HIGH8.8Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Dat...
CVE-2025-13000HIGH7.7The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated u...
CVE-2025-13387HIGH7.2The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome...
CVE-2025-20768HIGH7.8In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of...
CVE-2025-20767HIGH7.8In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of p...
CVE-2025-20766HIGH7.8In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation ...
CVE-2025-20764HIGH7.8In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2025-20763HIGH7.8In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2025-12529HIGH8.8The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ...
CVE-2025-58482HIGH7.3Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privile...
CVE-2025-58481HIGH7.8Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privil...
CVE-2025-58480HIGH7.5Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now