2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61593HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI ...
CVE-2025-61592HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific ...
CVE-2025-46817HIGH8.8Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-61591HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit...
CVE-2025-61590HIGH7.5Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R...
CVE-2025-56551HIGH8.2An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo...
CVE-2025-60787HIGH7.2MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name...
CVE-2025-55972HIGH7.5A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni...
CVE-2025-34226HIGH7.1OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field suppli...
CVE-2025-59489HIGH7.4Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi...
CVE-2025-9561HIGH8.8The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic...
CVE-2025-9213HIGH8.8The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due...
CVE-2025-9212HIGH7.5The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-9200HIGH7.5The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQ...
CVE-2025-27237HIGH7.3In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged ...
CVE-2025-10582HIGH8.8The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and ...
CVE-2025-11234HIGH7.5A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc...
CVE-2025-11223HIGH8.4Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead ...
CVE-2025-0616HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center ...
CVE-2025-59536HIGH8.8Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta...
CVE-2025-59300HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-59299HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-59298HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-59297HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-61668HIGH8.7Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now