2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70298HIGH8.2GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.
CVE-2025-66417CRITICAL9.8GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQ...
CVE-2025-66292HIGH8.1DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vu...
CVE-2025-62193CRITICAL9.8Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests ...
CVE-2025-67246HIGH7.3A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control ...
CVE-2025-67079CRITICAL9.8File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng...
CVE-2025-67078MEDIUM6.1Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary...
CVE-2025-67077HIGH8.8File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions al...
CVE-2025-67076HIGH7.5Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read fil...
CVE-2025-64516HIGH7.5GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GL...
CVE-2025-61973HIGH8.8A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A...
CVE-2025-71019HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. T...
CVE-2025-70744HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. ...
CVE-2025-67084CRITICAL9.9File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files int...
CVE-2025-67083MEDIUM5.3Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the ...
CVE-2025-67082MEDIUM6.5An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para...
CVE-2025-67081MEDIUM4.9An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro...
CVE-2025-13859MEDIUM6.4The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-13062HIGH8.8The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin...
CVE-2025-12895MEDIUM5.3The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending du...
CVE-2025-14457HIGH7.4The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2025-14448MEDIUM5.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Chec...
CVE-2025-14058LOW3.2A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us...
CVE-2025-13455HIGH7.8A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T...
CVE-2025-13454MEDIUM6.8A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now