2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62689HIGH8.7NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co...
CVE-2025-59777HIGH8.7NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co...
CVE-2025-12613HIGH8.8Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing o...
CVE-2025-12867HIGH8.6EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to u...
CVE-2025-12927HIGH7.2A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the fi...
CVE-2025-12926HIGH8.8A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function...
CVE-2025-12865HIGH8.8U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to in...
CVE-2025-12864HIGH8.8U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to in...
CVE-2025-12922HIGH8.8A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /...
CVE-2025-12921HIGH8.8A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknow...
CVE-2025-12399HIGH7.2The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss...
CVE-2025-11967HIGH7.2The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr...
CVE-2025-12099HIGH7.2The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object ...
CVE-2025-9334HIGH8.8The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all...
CVE-2025-12161HIGH8.8The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2025-11452HIGH7.5The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' ...
CVE-2025-64496HIGH8Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and ...
CVE-2025-64492HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0...
CVE-2025-64490HIGH8.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64489HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64488HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-12907HIGH8.8Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker...
CVE-2025-37736HIGH8.8Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can...
CVE-2025-60574HIGH7.5A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles...
CVE-2025-64439HIGH7.4LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now