2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40210HIGH7.5In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operation...
CVE-2025-13138HIGH7.5The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec...
CVE-2025-12160HIGH7.2The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p...
CVE-2025-13156HIGH8.8The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi...
CVE-2025-13322HIGH8.1The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2025-13159HIGH7.1The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG ...
CVE-2025-12138HIGH8.8The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida...
CVE-2025-12135HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi...
CVE-2025-11985HIGH8.8The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc...
CVE-2025-64695HIGH8.4Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitr...
CVE-2025-58097HIGH7.8The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u...
CVE-2025-64751HIGH8.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-62164HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor...
CVE-2025-64660HIGH8Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne...
CVE-2025-36072HIGH8.8IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi...
CVE-2025-61138HIGH7.5Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
CVE-2025-36160HIGH7.5IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in...
CVE-2025-13087HIGH7.5A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code ex...
CVE-2025-64770HIGH7The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may all...
CVE-2025-62674HIGH7The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an a...
CVE-2025-25613HIGH7.5FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2...
CVE-2025-48986HIGH8.8Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe...
CVE-2025-63889HIGH7.5The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary fil...
CVE-2025-62709HIGH8.8ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php cause...
CVE-2025-12121HIGH7.3Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now