2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55796HIGH7.5The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflow...
CVE-2025-53843HIGH7.5A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO...
CVE-2025-47761HIGH7.8An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7...
CVE-2025-46776HIGH7.8A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 t...
CVE-2025-46373HIGH7.8A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F...
CVE-2025-34324HIGH7.8GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The mani...
CVE-2025-33184HIGH7.8NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod...
CVE-2025-33183HIGH7.8NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod...
CVE-2025-63800HIGH7.5The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty s...
CVE-2025-63602HIGH7.3A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MS...
CVE-2025-63408HIGH7.8Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacke...
CVE-2025-12383HIGH7.4In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such...
CVE-2025-59113HIGH7.5Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt co...
CVE-2025-13347HIGH8.8A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of t...
CVE-2025-13346HIGH8.8A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the f...
CVE-2025-6670HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method...
CVE-2025-13345HIGH8.8A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue ...
CVE-2025-41737HIGH7.5Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
CVE-2025-41736HIGH8.8A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th...
CVE-2025-41735HIGH8.8A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem...
CVE-2025-4212HIGH7.2The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl...
CVE-2025-13069HIGH8.8The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, ...
CVE-2025-12955HIGH7.5The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions ...
CVE-2025-13088HIGH8.8The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up ...
CVE-2025-12775HIGH8.8The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now