2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-35432HIGH7.5CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker...
CVE-2025-10602HIGH8.8A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknow...
CVE-2025-40933HIGH7.5Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an...
CVE-2025-10595HIGH8.8A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is so...
CVE-2025-10205HIGH8.8Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and ...
CVE-2025-10594HIGH8.8A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an ...
CVE-2025-10593HIGH8.8A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio...
CVE-2025-10592HIGH8.8A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknow...
CVE-2025-8411HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T...
CVE-2025-10157HIGH7.8A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remot...
CVE-2025-10155HIGH7.8An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0...
CVE-2025-59457HIGH7.7In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
CVE-2025-9450HIGH7.8A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release...
CVE-2025-9449HIGH7.8A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS De...
CVE-2025-9447HIGH7.8An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR...
CVE-2025-9216HIGH8.8The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-10058HIGH8.1The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion du...
CVE-2025-10057HIGH8.8The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in a...
CVE-2025-10042HIGH7.5The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc...
CVE-2025-59518HIGH8In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It ...
CVE-2025-59307HIGH8.4RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri...
CVE-2025-58116HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and...
CVE-2025-10589HIGH8.8The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenti...
CVE-2025-10143HIGH7.5The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0...
CVE-2025-37127HIGH7.2A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now