2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56401HIGH7.6ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
CVE-2025-44018HIGH8.3A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft...
CVE-2025-40213HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set...
CVE-2025-10555HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer ...
CVE-2025-12970HIGH8.8The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit...
CVE-2025-11921HIGH8.5iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c...
CVE-2025-65998HIGH7.5Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though ...
CVE-2025-65495HIGH7.5Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t...
CVE-2025-65494HIGH7.5NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker...
CVE-2025-65493HIGH7.5NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servic...
CVE-2025-41016HIGH8.7Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images...
CVE-2025-41729HIGH7.5An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denia...
CVE-2025-12741HIGH7.7A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, ca...
CVE-2025-12740HIGH7.7A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML,...
CVE-2025-12739HIGH7.3An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would exe...
CVE-2025-13586HIGH7.2A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file...
CVE-2025-12629HIGH7.1The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-7402HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In...
CVE-2025-13581HIGH8.8A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-13580HIGH8.8A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.ph...
CVE-2025-13579HIGH8.8A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php....
CVE-2025-13576HIGH8.8A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /ad...
CVE-2025-13575HIGH8.8A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of t...
CVE-2025-13574HIGH7.2A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd o...
CVE-2025-13573HIGH8.8A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now