2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56392HIGH8.1An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack...
CVE-2025-56132HIGH7.3LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli...
CVE-2025-23293HIGH8.7NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause...
CVE-2025-6034HIGH8.5There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor ...
CVE-2025-6033HIGH8.5There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in N...
CVE-2025-56572HIGH7.5An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.
CVE-2025-56571HIGH7.5Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand...
CVE-2025-7779HIGH8.8Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True ...
CVE-2025-56301HIGH7.5An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi...
CVE-2025-11178HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...
CVE-2025-9230HIGH7.5Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou...
CVE-2025-11153HIGH7.5JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
CVE-2025-11152HIGH8.6Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143....
CVE-2025-9993HIGH8.1The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...
CVE-2025-9991HIGH8.1The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2025-8877HIGH7.5The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in...
CVE-2025-8122HIGH8.8Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ...
CVE-2025-8121HIGH8.8Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ...
CVE-2025-8117HIGH7.5PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d...
CVE-2025-7052HIGH8.8The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1...
CVE-2025-7038HIGH8.2The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with...
CVE-2025-59668HIGH8.7Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte...
CVE-2025-41098HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con...
CVE-2025-11149HIGH7.5This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package...
CVE-2025-10991HIGH7The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now