2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56572HIGH7.5An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.
CVE-2025-56571HIGH7.5Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand...
CVE-2025-7779HIGH8.8Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True ...
CVE-2025-56301HIGH7.5An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi...
CVE-2025-11178HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...
CVE-2025-9230HIGH7.5Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou...
CVE-2025-11153HIGH7.5JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
CVE-2025-11152HIGH8.6Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143....
CVE-2025-9993HIGH8.1The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...
CVE-2025-9991HIGH8.1The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2025-8877HIGH7.5The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in...
CVE-2025-8122HIGH8.8Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ...
CVE-2025-8121HIGH8.8Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ...
CVE-2025-8117HIGH7.5PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d...
CVE-2025-7052HIGH8.8The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1...
CVE-2025-7038HIGH8.2The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with...
CVE-2025-59668HIGH8.7Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte...
CVE-2025-41098HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con...
CVE-2025-11149HIGH7.5This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package...
CVE-2025-10991HIGH7The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have ...
CVE-2025-59952HIGH8.7MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp...
CVE-2025-59942HIGH7.5go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it v...
CVE-2025-43813HIGH8.2Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.10...
CVE-2025-36245HIGH8.8IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary comma...
CVE-2025-59933HIGH7.8libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now