2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10214HIGH7.8DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc...
CVE-2025-10213HIGH7.8DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc...
CVE-2025-36759HIGH8.7Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive informa...
CVE-2025-7049HIGH8.8The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions u...
CVE-2025-41714HIGH8.8The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an ...
CVE-2025-10049HIGH7.2The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ...
CVE-2025-10040HIGH7.7The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of dat...
CVE-2025-10001HIGH7.2The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m...
CVE-2025-59042HIGH7PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being ap...
CVE-2025-59038HIGH8.6Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9...
CVE-2025-10172HIGH8.8A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/for...
CVE-2025-54260HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra...
CVE-2025-54259HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that c...
CVE-2025-54258HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in ar...
CVE-2025-49461HIGH7.4Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service ...
CVE-2025-49460HIGH7.5Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denia...
CVE-2025-49459HIGH7.8Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authentic...
CVE-2025-10171HIGH8.8A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the ...
CVE-2025-59037HIGH8.6DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Nod...
CVE-2025-58765HIGH7.1wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site ...
CVE-2025-58763HIGH7.2Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Taut...
CVE-2025-54245HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54244HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r...
CVE-2025-54243HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54084HIGH8.5OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now