2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-20767HIGH7.8In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of p...
CVE-2025-20766HIGH7.8In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation ...
CVE-2025-20764HIGH7.8In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2025-20763HIGH7.8In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2025-12529HIGH8.8The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ...
CVE-2025-58482HIGH7.3Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privile...
CVE-2025-58481HIGH7.8Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privil...
CVE-2025-58480HIGH7.5Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access o...
CVE-2025-58479HIGH7.5Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bo...
CVE-2025-58478HIGH7.5Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-b...
CVE-2025-21080HIGH7.1Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local att...
CVE-2025-66448HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote co...
CVE-2025-66313HIGH7.2ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL in...
CVE-2025-66304HIGH7.2Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section...
CVE-2025-66300HIGH8.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can ...
CVE-2025-66299HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S...
CVE-2025-66298HIGH7.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav config...
CVE-2025-66297HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or e...
CVE-2025-66296HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin p...
CVE-2025-66295HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new use...
CVE-2025-66294HIGH8.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists ...
CVE-2025-66206HIGH8.6Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path...
CVE-2025-65840HIGH8.8PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
CVE-2025-55749HIGH7.5XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is usin...
CVE-2025-65838HIGH7.5PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now