2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7654HIGH8.8Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes ...
CVE-2025-8218HIGH8.8The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the...
CVE-2025-54156HIGH7.5The Sante PACS Server Web Portal sends credential information without encryption.
CVE-2025-53948HIGH8.7The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a deni...
CVE-2025-52584HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-46269HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-53705HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-41392HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-8098HIGH8.5An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate pri...
CVE-2025-55588HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/form...
CVE-2025-55587HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/f...
CVE-2025-55586HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFi...
CVE-2025-53192HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons...
CVE-2025-4371HIGH7A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacke...
CVE-2025-32992HIGH8.5Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
CVE-2025-55300HIGH8.6Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for moni...
CVE-2025-55291HIGH7.1Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa...
CVE-2025-55283HIGH7.2aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that...
CVE-2025-55282HIGH7.2aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that...
CVE-2025-55201HIGH8.5Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write...
CVE-2025-4962HIGH7.7An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna...
CVE-2025-36120HIGH8.8IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s...
CVE-2025-33100HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, whi...
CVE-2025-33090HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr...
CVE-2025-1759HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now