2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13345HIGH8.8A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue ...
CVE-2025-41737HIGH7.5Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
CVE-2025-41736HIGH8.8A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th...
CVE-2025-41735HIGH8.8A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem...
CVE-2025-4212HIGH7.2The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl...
CVE-2025-13069HIGH8.8The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, ...
CVE-2025-12955HIGH7.5The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions ...
CVE-2025-13088HIGH8.8The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up ...
CVE-2025-12775HIGH8.8The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc...
CVE-2025-12528HIGH8.1The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1...
CVE-2025-12411HIGH7.1The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet...
CVE-2025-11620HIGH7.2The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2025-8727HIGH7.2There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web ...
CVE-2025-8076HIGH7.2There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web ...
CVE-2025-10089HIGH7.7Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S ...
CVE-2025-48593HIGH8In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. Th...
CVE-2025-12974HIGH8.1The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-8693HIGH8.8A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(A...
CVE-2025-6599HIGH7.5An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C...
CVE-2025-13325HIGH8.8A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown functi...
CVE-2025-13306HIGH8.8A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the fu...
CVE-2025-13230HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-13229HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-13228HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-13227HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now