2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-56383HIGH8.4Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. N...
CVE-2025-55847HIGH8.8Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerab...
CVE-2025-45994HIGH7.5An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a...
CVE-2025-59844HIGH7.7SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command ...
CVE-2025-55848HIGH8.8An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interfa...
CVE-2025-11030HIGH7.3A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837...
CVE-2025-11029HIGH8.8A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipul...
CVE-2025-58385HIGH7.1In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (th...
CVE-2025-11028HIGH7.5A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image H...
CVE-2025-36326HIGH7.5IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain ...
CVE-2025-36274HIGH7.5IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which ...
CVE-2025-11026HIGH7.5A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality...
CVE-2025-11018HIGH7.5A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of ...
CVE-2025-9267HIGH7In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attemp...
CVE-2025-11014HIGH7.8A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encod...
CVE-2025-11012HIGH7.8A vulnerability was determined in BehaviorTree up to 4.7.0. This affects the function ParseScript of the file /src/scrip...
CVE-2025-11042HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and...
CVE-2025-10544HIGH8.6Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versio...
CVE-2025-9958HIGH7.7An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18...
CVE-2025-7691HIGH8.8A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 pri...
CVE-2025-60173HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored X...
CVE-2025-60172HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This ...
CVE-2025-60171HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.c...
CVE-2025-60170HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Store...
CVE-2025-60169HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now