2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58261HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-htt...
CVE-2025-58259HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in scriptsbundle Nokri nokri allows Cross Site Request Forgery.This issu...
CVE-2025-58250HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affect...
CVE-2025-58244HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This issue affects...
CVE-2025-58015HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-make...
CVE-2025-58013HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affe...
CVE-2025-57977HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-inv...
CVE-2025-57968HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestau...
CVE-2025-57925HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-57919HIGH7.2Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.Th...
CVE-2025-57918HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affec...
CVE-2025-57685HIGH8.8The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B...
CVE-2025-53468HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.c...
CVE-2025-53465HIGH7.2Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This ...
CVE-2025-53450HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59420HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific...
CVE-2025-57440HIGH7.5The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated ...
CVE-2025-57439HIGH8.8Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo...
CVE-2025-55888HIGH7.3Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can...
CVE-2025-43953HIGH8.8In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr...
CVE-2025-59335HIGH7.1CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration...
CVE-2025-57434HIGH8.8Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The...
CVE-2025-57431HIGH8.8The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici...
CVE-2025-10807HIGH8.8A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unk...
CVE-2025-10806HIGH8.8A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now