2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58013HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affe...
CVE-2025-57977HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-inv...
CVE-2025-57968HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestau...
CVE-2025-57925HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-57919HIGH7.2Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.Th...
CVE-2025-57918HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affec...
CVE-2025-57685HIGH8.8The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B...
CVE-2025-53468HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.c...
CVE-2025-53465HIGH7.2Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This ...
CVE-2025-53450HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59420HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific...
CVE-2025-57440HIGH7.5The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated ...
CVE-2025-57439HIGH8.8Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo...
CVE-2025-55888HIGH7.3Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can...
CVE-2025-43953HIGH8.8In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr...
CVE-2025-59335HIGH7.1CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration...
CVE-2025-57434HIGH8.8Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The...
CVE-2025-57431HIGH8.8The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici...
CVE-2025-10807HIGH8.8A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unk...
CVE-2025-10806HIGH8.8A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unkno...
CVE-2025-57605HIGH8.8Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users ...
CVE-2025-57430HIGH7.5Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When access...
CVE-2025-36202HIGH8.8IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute co...
CVE-2025-35041HIGH7.7Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A r...
CVE-2025-10805HIGH8.8A vulnerability was determined in Campcodes Online Beauty Parlor Management System 1.0. This affects an unknown part of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now