2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12233HIGH8.8A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromSafeUrlFilter of the file /gofor...
CVE-2025-12055HIGH7.5HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in a...
CVE-2025-12225HIGH8.8A vulnerability has been found in Tenda AC6 15.03.06.50. This issue affects some unknown processing of the file /goform/...
CVE-2025-12223HIGH8.8A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/...
CVE-2025-12222HIGH8.8A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some u...
CVE-2025-12214HIGH8.8A vulnerability was detected in Tenda O3 1.0.0.10(2478). This issue affects the function SetValue/GetValue of the file /...
CVE-2025-12213HIGH8.8A security vulnerability has been detected in Tenda O3 1.0.0.10(2478). This vulnerability affects the function SetValue/...
CVE-2025-12212HIGH8.8A weakness has been identified in Tenda O3 1.0.0.10(2478). This affects the function SetValue/GetValue of the file /gofo...
CVE-2025-12209HIGH8.8A vulnerability was determined in Tenda O3 1.0.0.10(2478). Affected is the function SetValue/GetValue of the file /gofor...
CVE-2025-12205HIGH7.8A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core...
CVE-2025-12204HIGH7.8A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rv...
CVE-2025-62986HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS.This is...
CVE-2025-62962HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio CloudSearch cloud-search allows Stored XSS.This issue...
CVE-2025-62957HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in NikanWP NikanWP WooCommerce Reporting wc-reports-lite allows Stored X...
CVE-2025-62956HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in iseremet Reloadly reloadly-topup-widget allows Stored XSS.This issue ...
CVE-2025-62945HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Eduard Pinuaga Linares Did Prestashop Display did-prestashop-display ...
CVE-2025-62934HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issu...
CVE-2025-62933HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.T...
CVE-2025-62896HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows St...
CVE-2025-62886HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored X...
CVE-2025-12201HIGH7.2A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1....
CVE-2025-11989HIGH8.1GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18...
CVE-2025-11447HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 1...
CVE-2025-10497HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and ...
CVE-2025-8709HIGH7.3A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite st...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now