2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43897Rejected reason: Not used
CVE-2025-43896Rejected reason: Not used
CVE-2025-43895Rejected reason: Not used
CVE-2025-43894Rejected reason: Not used
CVE-2025-43893Rejected reason: Not used
CVE-2025-3284MEDIUM4.3The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln...
CVE-2025-3278CRITICAL9.8The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0....
CVE-2025-2010HIGH7.5The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injecti...
CVE-2025-43903LOW3.3NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting...
CVE-2025-3796HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unk...
CVE-2025-32953HIGH8.7z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubunt...
CVE-2025-29058CRITICAL9.8An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.
CVE-2025-3795LOW3.4A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2025-36625MEDIUM4.3In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http...
CVE-2025-32377MEDIUM6.5Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models...
CVE-2025-28197CRITICAL9.1Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
CVE-2025-25985LOW2.6An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim...
CVE-2025-25984MEDIUM6.8An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim...
CVE-2025-25983LOW3.4An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64...
CVE-2025-28355MEDIUM4.7Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execu...
CVE-2025-24914HIGH7.8When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu...
CVE-2025-29513MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in ...
CVE-2025-29512MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and...
CVE-2025-28242CRITICAL9.8Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session ...
CVE-2025-28238CRITICAL9.8Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now