2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49897HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical ...
CVE-2025-5048HIGH7.8A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerabili...
CVE-2025-5047HIGH7.8A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability....
CVE-2025-5046HIGH7.8A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-54989HIGH7.5Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL poin...
CVE-2025-24975HIGH8.8Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnera...
CVE-2025-54475HIGH8.7A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execut...
CVE-2025-54474HIGH8.5A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged use...
CVE-2025-1929HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Tekno...
CVE-2025-9046HIGH8.8A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform...
CVE-2025-9025HIGH8.8A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown ...
CVE-2025-9023HIGH8.8A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed o...
CVE-2025-7650HIGH7.5The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1...
CVE-2025-7641HIGH7.5The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient...
CVE-2025-9016HIGH7A vulnerability has been found in Mechrevo Control Center GX V2 5.56.51.48. Affected is an unknown function of the file ...
CVE-2025-9007HIGH8.8A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the fil...
CVE-2025-9006HIGH8.8A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of ...
CVE-2025-9001HIGH7.5A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HT...
CVE-2025-8342HIGH8.1The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypas...
CVE-2025-6025HIGH7.5The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all ver...
CVE-2025-9000HIGH7A vulnerability was detected in Mechrevo Control Center GX V2 5.56.51.48. Impacted is an unknown function of the compone...
CVE-2025-31987HIGH7.5HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource...
CVE-2025-8978HIGH8.1A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component bo...
CVE-2025-55708HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech System...
CVE-2025-53587HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo findgo allows Cross Site Request Forgery.This issue ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now