2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10702HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,...
CVE-2025-63219HIGH7.5The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se...
CVE-2025-13395HIGH7.3A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted el...
CVE-2025-12472HIGH7.1An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git direct...
CVE-2025-11230HIGH7.5Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially ...
CVE-2025-13035HIGH8The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. ...
CVE-2025-12484HIGH7.2The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for...
CVE-2025-12056HIGH8.3Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.
CVE-2025-11243HIGH8.3Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo...
CVE-2025-13145HIGH7.2The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in al...
CVE-2025-12646HIGH7.5The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u...
CVE-2025-12426HIGH7.5The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-12852HIGH8.4DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC ...
CVE-2025-65015HIGH7.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2025-64324HIGH7.7KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos...
CVE-2025-62406HIGH8.8Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset ...
CVE-2025-63215HIGH7.2The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u...
CVE-2025-63227HIGH7.2The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne...
CVE-2025-37162HIGH8.8A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduc...
CVE-2025-37161HIGH7.5A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke...
CVE-2025-63955HIGH7.5A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst...
CVE-2025-61662HIGH7.8A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh...
CVE-2025-60455HIGH8.4Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca...
CVE-2025-37163HIGH7.2A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave ...
CVE-2025-37159HIGH7.3A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now