2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5555HIGH7.8A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in th...
CVE-2025-11691HIGH7.5The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PP...
CVE-2025-11517HIGH7.5The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu...
CVE-2025-62646HIGH7.7The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the st...
CVE-2025-62644HIGH7.7The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares...
CVE-2025-62643HIGH8.6The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in ...
CVE-2025-62642HIGH8.6The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign...
CVE-2025-11914HIGH7.5A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function ...
CVE-2025-11912HIGH8.8A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file ...
CVE-2025-11911HIGH8.8A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t...
CVE-2025-11910HIGH8.8A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct...
CVE-2025-11909HIGH8.8A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi...
CVE-2025-11908HIGH8.8A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f...
CVE-2025-62422HIGH8.8DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datas...
CVE-2025-62420HIGH8.8DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vuln...
CVE-2025-62419HIGH7.5DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vuln...
CVE-2025-62171HIGH7.5ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick ...
CVE-2025-62168HIGH7.5Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential...
CVE-2025-62356HIGH7.5A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local f...
CVE-2025-59043HIGH7.5OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects aft...
CVE-2025-26625HIGH8.6Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re...
CVE-2025-11905HIGH8.8A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the...
CVE-2025-55085HIGH7.5In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsi...
CVE-2025-11904HIGH7.2A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo...
CVE-2025-48044HIGH8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now