2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10176HIGH7.2The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici...
CVE-2025-45587HIGH7A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of...
CVE-2025-45586HIGH7.5An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a ...
CVE-2025-45584HIGH7.5Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download ...
CVE-2025-43796HIGH7.5Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA...
CVE-2025-10325HIGH8.8A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file...
CVE-2025-4235HIGH7.2An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the ...
CVE-2025-57579HIGH8An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code vi...
CVE-2025-57578HIGH8An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password
CVE-2025-57577HIGH8An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: t...
CVE-2025-39797HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates ...
CVE-2025-39796HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: lapbether: ignore ops-locked netdevs Syzkalle...
CVE-2025-39793HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/memmap: cast nr_pages to size_t before shi...
CVE-2025-59054HIGH8.5dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execu...
CVE-2025-10318HIGH8.8A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of t...
CVE-2025-6638HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-27240HIGH7.2A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visibl...
CVE-2025-27234HIGH7.3Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex...
CVE-2025-10265HIGH8.8Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att...
CVE-2025-7448HIGH8.6Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the ...
CVE-2025-9086HIGH7.51. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak...
CVE-2025-8575HIGH7.2The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i...
CVE-2025-6454HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18...
CVE-2025-2256HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-10291HIGH8.8A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now