2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10595HIGH8.8A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is so...
CVE-2025-10205HIGH8.8Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and ...
CVE-2025-10594HIGH8.8A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an ...
CVE-2025-10593HIGH8.8A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio...
CVE-2025-10592HIGH8.8A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknow...
CVE-2025-8411HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T...
CVE-2025-10157HIGH7.8A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remot...
CVE-2025-10155HIGH7.8An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0...
CVE-2025-59457HIGH7.7In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
CVE-2025-9450HIGH7.8A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release...
CVE-2025-9449HIGH7.8A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS De...
CVE-2025-9447HIGH7.8An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR...
CVE-2025-9216HIGH8.8The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-10058HIGH8.1The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion du...
CVE-2025-10057HIGH8.8The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in a...
CVE-2025-10042HIGH7.5The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc...
CVE-2025-59518HIGH8In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It ...
CVE-2025-59307HIGH8.4RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri...
CVE-2025-58116HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and...
CVE-2025-10589HIGH8.8The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenti...
CVE-2025-10143HIGH7.5The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0...
CVE-2025-37127HIGH7.2A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authe...
CVE-2025-37126HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote...
CVE-2025-37125HIGH7.5A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation coul...
CVE-2025-37124HIGH8.6A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass fir...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now