2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48307HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images seo-for-images allows Stored XSS.This issue ...
CVE-2025-48306HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner savyour-affiliate-partne...
CVE-2025-48304HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin gn-xml-sitemap allows Stor...
CVE-2025-48109HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup xm-backup allows Stored XSS.This issue affects...
CVE-2025-48963HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2025-58081HIGH8.7Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allo...
CVE-2025-58072HIGH8.7Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear...
CVE-2025-54819HIGH7.1Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear...
CVE-2025-53396HIGH7.3Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0....
CVE-2025-46409HIGH8.7Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If thi...
CVE-2025-58322HIGH7.8NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM ...
CVE-2025-7812HIGH8.8The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-40779HIGH7.5If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the clien...
CVE-2025-55618HIGH7.3In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field i...
CVE-2025-4225HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18....
CVE-2025-58218HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition small-package-q...
CVE-2025-58217HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News instant-breaking-news allows Stored...
CVE-2025-55422HIGH8.8In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
CVE-2025-51667HIGH7An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-...
CVE-2025-50979HIGH8.6NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The sear...
CVE-2025-34161HIGH8.8Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo...
CVE-2025-34159HIGH8.8Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d...
CVE-2025-20344HIGH7.2A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack...
CVE-2025-20317HIGH7.1A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll...
CVE-2025-20241HIGH7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now