2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13145HIGH7.2The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in al...
CVE-2025-12646HIGH7.5The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u...
CVE-2025-12426HIGH7.5The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-12852HIGH8.4DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC ...
CVE-2025-65015HIGH7.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2025-64324HIGH7.7KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos...
CVE-2025-62406HIGH8.8Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset ...
CVE-2025-63215HIGH7.2The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u...
CVE-2025-63227HIGH7.2The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne...
CVE-2025-37162HIGH8.8A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduc...
CVE-2025-37161HIGH7.5A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke...
CVE-2025-63955HIGH7.5A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst...
CVE-2025-61662HIGH7.8A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh...
CVE-2025-60455HIGH8.4Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca...
CVE-2025-37163HIGH7.2A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave ...
CVE-2025-37159HIGH7.3A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticate...
CVE-2025-37158HIGH8.8A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti...
CVE-2025-37157HIGH8.8A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti...
CVE-2025-37155HIGH7.8A vulnerability in the SSH restricted shell interface of the network management services allows improper access control ...
CVE-2025-64076HIGH7.5Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C ext...
CVE-2025-63829HIGH7.5eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction...
CVE-2025-58692HIGH8.8An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi...
CVE-2025-58413HIGH7.5A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO...
CVE-2025-58034HIGH7.2An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-56527HIGH7.5Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now