2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10635HIGH7.7The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2025-11204HIGH7.2The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-10494HIGH8.1The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion d...
CVE-2025-11426HIGH8.8A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerabil...
CVE-2025-61787HIGH8.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command ...
CVE-2025-48981HIGH8.6An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet t...
CVE-2025-11417HIGH8.8A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unk...
CVE-2025-11410HIGH8.8A flaw has been found in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the...
CVE-2025-62186HIGH7.8Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio b...
CVE-2025-62185HIGH7.8In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, a...
CVE-2025-11409HIGH8.8A vulnerability was detected in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unkno...
CVE-2025-6242HIGH7.1A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimod...
CVE-2025-61910HIGH7.5The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A BP...
CVE-2025-44823HIGH8.8Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi...
CVE-2025-43727HIGH7.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-61784HIGH8.1LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF...
CVE-2025-43912HIGH7.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43909HIGH7.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43891HIGH7.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43889HIGH7.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4,...
CVE-2025-11192HIGH8.6A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on...
CVE-2025-43914HIGH7.8Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS...
CVE-2025-36156HIGH7.8IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused ...
CVE-2025-61772HIGH7.5Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` c...
CVE-2025-61771HIGH7.5Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now