2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-50735HIGH7.5Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot ...
CVE-2025-63441HIGH7.3Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u...
CVE-2025-60785HIGH8.8A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attac...
CVE-2025-60503HIGH8.7A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 whe...
CVE-2025-36093HIGH7.4IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content ...
CVE-2025-11761HIGH7.8A potential security vulnerability has been identified in the HP Client Management Script Library software, which might ...
CVE-2025-48397HIGH7.1The privileged user could log in without sufficient credentials after enabling an application protocol. This security is...
CVE-2025-48396HIGH8.3Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This sec...
CVE-2025-12503HIGH7.1EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote a...
CVE-2025-12615HIGH8.1A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of...
CVE-2025-12610HIGH7.2A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/v...
CVE-2025-12609HIGH8.8A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality o...
CVE-2025-12594HIGH7.2A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown...
CVE-2025-12593HIGH7.2A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u...
CVE-2025-12601HIGH7.5Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-36367HIGH8.8IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz...
CVE-2025-6990HIGH8.8The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via ...
CVE-2025-6574HIGH8.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-12171HIGH8.8The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va...
CVE-2025-11755HIGH8.8The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar...
CVE-2025-10487HIGH7.3The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up t...
CVE-2025-5949HIGH8.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-11995HIGH7.2The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al...
CVE-2025-11920HIGH8.8The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14...
CVE-2025-63561HIGH7.5Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Serv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now