2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55732HIGH7.5Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injecti...
CVE-2025-55731HIGH8.8Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would nor...
CVE-2025-55498HIGH7.5Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime fu...
CVE-2025-55482HIGH7.5Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
CVE-2025-51991HIGH8.8XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, spe...
CVE-2025-36114HIGH7.5IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An a...
CVE-2025-55503HIGH7.3Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInf...
CVE-2025-55483HIGH7.5Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters mac...
CVE-2025-54926HIGH7.2CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-54925HIGH7.5CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ...
CVE-2025-54924HIGH7.5CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ...
CVE-2025-54923HIGH8.7CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of...
CVE-2025-50503HIGH8.8A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the O...
CVE-2025-30256HIGH7.5A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A spe...
CVE-2025-24496HIGH7.5An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.1...
CVE-2025-8453HIGH8.4CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code exe...
CVE-2025-57729HIGH7.3In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
CVE-2025-57727HIGH7.5In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
CVE-2025-5261HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Ex...
CVE-2025-5260HIGH8.6Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Requ...
CVE-2025-55715HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows...
CVE-2025-54750HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54735HIGH8.8Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This i...
CVE-2025-54677HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPres...
CVE-2025-54670HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now