2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10105HIGH8.8A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the f...
CVE-2025-52389HIGH8.8An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke...
CVE-2025-9112HIGH8.8The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do...
CVE-2025-55849HIGH8.4WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CVE-2025-56265HIGH8.8An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac...
CVE-2025-10098HIGH8.8A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the fil...
CVE-2025-59033HIGH7.4The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries...
CVE-2025-56630HIGH7.3FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Colum...
CVE-2025-55998HIGH8.1A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacke...
CVE-2025-40930HIGH7.5JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing craft...
CVE-2025-40928HIGH7.5JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl...
CVE-2025-36855HIGH8.8A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. P...
CVE-2025-36854HIGH8.1A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream whi...
CVE-2025-36853HIGH7.5A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: ...
CVE-2025-10093HIGH7.5A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi...
CVE-2025-41708HIGH7.4Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke...
CVE-2025-41682HIGH8.8An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufactu...
CVE-2025-41664HIGH7.5A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates...
CVE-2025-10087HIGH7.2A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknow...
CVE-2025-8085HIGH8.6The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoi...
CVE-2025-10085HIGH8.8A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u...
CVE-2025-10083HIGH8.8A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some un...
CVE-2025-10081HIGH7.2A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/p...
CVE-2025-48042HIGH7.1Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2025-39730HIGH7.8In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_de...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now