2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57106HIGH7.5Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi...
CVE-2025-12501HIGH7.5Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-...
CVE-2025-64386HIGH7.7The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of...
CVE-2025-33003HIGH7.8IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi...
CVE-2025-64366HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu...
CVE-2025-64364HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64363HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64360HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64359HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64353HIGH8.8Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P...
CVE-2025-58149HIGH7.5When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the...
CVE-2025-58148HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-58147HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-12115HIGH7.5The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi...
CVE-2025-11843HIGH8.8Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun...
CVE-2025-62232HIGH7.5Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f...
CVE-2025-30189HIGH7.4When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached ...
CVE-2025-30188HIGH7.5Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform...
CVE-2025-10897HIGH8.6The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi...
CVE-2025-7846HIGH8.8The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-63675HIGH8.8cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt...
CVE-2025-54763HIGH8.6FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user...
CVE-2025-8849HIGH7.5LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api...
CVE-2025-6176HIGH7.5Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio...
CVE-2025-52664HIGH8.8SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now