2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31425HIGH7.5Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Co...
CVE-2025-31007HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alvind Billplz Add...
CVE-2025-30998HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rico Macchi WP Lin...
CVE-2025-30639HIGH7.5Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Acce...
CVE-2025-30635HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30626HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multi...
CVE-2025-29014HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu al...
CVE-2025-28999HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce...
CVE-2025-28975HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Alike - W...
CVE-2025-25172HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-24766HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-8956HIGH8.8A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/c...
CVE-2025-54472HIGH7.5Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows atta...
CVE-2025-48862HIGH7.1Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi...
CVE-2025-48860HIGH8A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) att...
CVE-2025-27388HIGH8.3Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user to...
CVE-2025-8940HIGH8.8A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of...
CVE-2025-8939HIGH8.8A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/Wifi...
CVE-2025-8937HIGH8.8A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /b...
CVE-2025-8931HIGH8.8A vulnerability was determined in code-projects Medical Store Management System 1.0. Affected is an unknown function of ...
CVE-2025-8930HIGH8.8A vulnerability was found in code-projects Medical Store Management System 1.0. This issue affects some unknown processi...
CVE-2025-55197HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads...
CVE-2025-55196HIGH7.1External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15...
CVE-2025-8929HIGH8.8A vulnerability has been found in code-projects Medical Store Management System 1.0. This vulnerability affects unknown ...
CVE-2025-8928HIGH8.8A vulnerability was identified in code-projects Medical Store Management System 1.0. This affects an unknown part of the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now