2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-63783HIGH7.6A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet...
CVE-2025-58469HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can the...
CVE-2025-58464HIGH7.5A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit...
CVE-2025-54167HIGH7.2A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains a...
CVE-2025-12861HIGH7.2A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the...
CVE-2025-12860HIGH7.2A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. ...
CVE-2025-12859HIGH7.2A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_...
CVE-2025-10968HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna...
CVE-2025-64343HIGH7.8(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 ...
CVE-2025-4519HIGH8.8The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala...
CVE-2025-64328HIGH7.2FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov...
CVE-2025-64184HIGH8.8Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constru...
CVE-2025-5483HIGH8.1The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi...
CVE-2025-58423HIGH8.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-se...
CVE-2025-12636HIGH7.1The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba...
CVE-2025-12036HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of b...
CVE-2025-11756HIGH8.8Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised t...
CVE-2025-11460HIGH8.8Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code vi...
CVE-2025-11458HIGH8.1Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of boun...
CVE-2025-64178HIGH8.9Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to dow...
CVE-2025-11211HIGH7.5Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out...
CVE-2025-11209HIGH8.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to ...
CVE-2025-11206HIGH7.1Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a...
CVE-2025-11205HIGH8.8Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the...
CVE-2025-64173HIGH7.5Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now