2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53589MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-53414MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-53405MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52872HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-52864HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-52863HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-52431MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52430MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52426MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-47208MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating...
CVE-2025-45286MEDIUM6.1A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script...
CVE-2025-44013MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-15438HIGH7.2A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file co...
CVE-2025-15437MEDIUM5.4A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl...
CVE-2025-15436CRITICAL9.8A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /wor...
CVE-2025-15435CRITICAL9.8A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksh...
CVE-2025-15434CRITICAL9.8A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The mani...
CVE-2025-15432HIGH7.5A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability af...
CVE-2025-15431HIGH8.8A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDir...
CVE-2025-15430HIGH8.8A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the function strcpy of the file /gof...
CVE-2025-15429HIGH8.8A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vulnerability is the function s...
CVE-2025-14072MEDIUM5.3The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the...
CVE-2025-13456MEDIUM6.1The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the...
CVE-2025-13153MEDIUM6.1The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting...
CVE-2025-12685MEDIUM6.5The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now