2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12615HIGH8.1A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of...
CVE-2025-12610HIGH7.2A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/v...
CVE-2025-12609HIGH8.8A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality o...
CVE-2025-12594HIGH7.2A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown...
CVE-2025-12593HIGH7.2A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u...
CVE-2025-12601HIGH7.5Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-36367HIGH8.8IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz...
CVE-2025-6990HIGH8.8The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via ...
CVE-2025-6574HIGH8.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-12171HIGH8.8The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va...
CVE-2025-11755HIGH8.8The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar...
CVE-2025-10487HIGH7.3The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up t...
CVE-2025-5949HIGH8.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-11995HIGH7.2The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al...
CVE-2025-11920HIGH8.8The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14...
CVE-2025-63561HIGH7.5Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Serv...
CVE-2025-10693HIGH7.6When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-...
CVE-2025-64349HIGH8.8ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, ...
CVE-2025-64348HIGH7.1ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the ...
CVE-2025-63458HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wi...
CVE-2025-63454HIGH7.5Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentContro...
CVE-2025-62618HIGH8.6ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u...
CVE-2025-12547HIGH8.1A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t...
CVE-2025-63459HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42...
CVE-2025-63465HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42288...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now