2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54374HIGH8.8Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code...
CVE-2025-57714HIGH7.8An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain...
CVE-2025-54153HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-53595HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-52656HIGH7.6HCL MyXalytics: 6.6.  is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatica...
CVE-2025-47212HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-46819HIGH7.1Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-46818HIGH7.3Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-44014HIGH8.8An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun...
CVE-2025-61593HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI ...
CVE-2025-61592HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific ...
CVE-2025-46817HIGH8.8Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-61591HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit...
CVE-2025-61590HIGH7.5Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R...
CVE-2025-56551HIGH8.2An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo...
CVE-2025-60787HIGH7.2MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name...
CVE-2025-55972HIGH7.5A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni...
CVE-2025-34226HIGH7.1OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field suppli...
CVE-2025-59489HIGH7.4Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi...
CVE-2025-9561HIGH8.8The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic...
CVE-2025-9213HIGH8.8The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due...
CVE-2025-9212HIGH7.5The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-9200HIGH7.5The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQ...
CVE-2025-27237HIGH7.3In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged ...
CVE-2025-10582HIGH8.8The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now