2025 CVE Vulnerabilities

45,328 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41714HIGH8.8The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an ...
CVE-2025-10049HIGH7.2The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ...
CVE-2025-10040HIGH7.7The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of dat...
CVE-2025-10001HIGH7.2The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m...
CVE-2025-59042HIGH7PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being ap...
CVE-2025-59038HIGH8.6Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9...
CVE-2025-10172HIGH8.8A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/for...
CVE-2025-54260HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra...
CVE-2025-54259HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that c...
CVE-2025-54258HIGH7.8Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in ar...
CVE-2025-49461HIGH7.4Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service ...
CVE-2025-49460HIGH7.5Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denia...
CVE-2025-49459HIGH7.8Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authentic...
CVE-2025-10171HIGH8.8A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the ...
CVE-2025-59037HIGH8.6DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Nod...
CVE-2025-58765HIGH7.1wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site ...
CVE-2025-58763HIGH7.2Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Taut...
CVE-2025-54245HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54244HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r...
CVE-2025-54243HIGH7.8Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-54084HIGH8.5OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated a...
CVE-2025-10170HIGH8.8A security vulnerability has been detected in UTT 1200GW up to 3.0.0-170831. This affects the function sub_4B48F8 of the...
CVE-2025-10169HIGH8.8A weakness has been identified in UTT 1200GW up to 3.0.0-170831. Affected by this issue is some unknown functionality of...
CVE-2025-7635HIGH7.7Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT...
CVE-2025-58762HIGH7.2Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now