2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56219HIGH7.1Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin...
CVE-2025-62577HIGH8.8ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged ...
CVE-2025-11944HIGH7.2A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control...
CVE-2025-11941HIGH8.1A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php...
CVE-2025-11940HIGH7.3A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of ...
CVE-2025-11939HIGH7.2A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu...
CVE-2025-11938HIGH8.1A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se...
CVE-2025-47410HIGH8.8Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all...
CVE-2025-9890HIGH8.8The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-5555HIGH7.8A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in th...
CVE-2025-11691HIGH7.5The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PP...
CVE-2025-11517HIGH7.5The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu...
CVE-2025-62646HIGH7.7The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the st...
CVE-2025-62644HIGH7.7The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares...
CVE-2025-62643HIGH8.6The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in ...
CVE-2025-62642HIGH8.6The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign...
CVE-2025-11914HIGH7.5A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function ...
CVE-2025-11912HIGH8.8A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file ...
CVE-2025-11911HIGH8.8A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t...
CVE-2025-11910HIGH8.8A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct...
CVE-2025-11909HIGH8.8A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi...
CVE-2025-11908HIGH8.8A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f...
CVE-2025-62422HIGH8.8DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datas...
CVE-2025-62420HIGH8.8DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vuln...
CVE-2025-62419HIGH7.5DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now