2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13536HIGH8.8The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida...
CVE-2025-7820HIGH7.5The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including...
CVE-2025-13680HIGH8.8The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ...
CVE-2025-12758HIGH7.7Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe...
CVE-2025-66314HIGH7.5Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper...
CVE-2025-0658HIGH8.7A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev...
CVE-2025-0657HIGH8.8A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed...
CVE-2025-66035HIGH7.7Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2025-66031HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R...
CVE-2025-64344HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64335HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64334HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64333HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64332HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64331HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64330HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-62593HIGH8.8Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited...
CVE-2025-65202HIGH8TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, explo...
CVE-2025-65278HIGH7.5An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers...
CVE-2025-12571HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and ...
CVE-2025-66028HIGH8.2OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable ...
CVE-2025-65966HIGH8.1OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea...
CVE-2025-65672HIGH7.5Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course sett...
CVE-2025-64129HIGH7.6Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the...
CVE-2025-55471HIGH7.5Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive inf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now