2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12921HIGH8.8A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknow...
CVE-2025-12399HIGH7.2The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss...
CVE-2025-11967HIGH7.2The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr...
CVE-2025-12099HIGH7.2The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object ...
CVE-2025-9334HIGH8.8The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all...
CVE-2025-12161HIGH8.8The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2025-11452HIGH7.5The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' ...
CVE-2025-64496HIGH8Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and ...
CVE-2025-64492HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0...
CVE-2025-64490HIGH8.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64489HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64488HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-12907HIGH8.8Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker...
CVE-2025-37736HIGH8.8Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can...
CVE-2025-60574HIGH7.5A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles...
CVE-2025-64439HIGH7.4LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2025-12875HIGH7.8A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems...
CVE-2025-64431HIGH8.7Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direc...
CVE-2025-36186HIGH7.8IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations co...
CVE-2025-33012HIGH8.8IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux coul...
CVE-2025-2534HIGH7.5IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ...
CVE-2025-9458HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili...
CVE-2025-64430HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2....
CVE-2025-64347HIGH7.5Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. ...
CVE-2025-57698HIGH7.5AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now