2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-30033HIGH8.5The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when...
CVE-2025-41686HIGH7.8A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain admin...
CVE-2025-8418HIGH8.8The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all v...
CVE-2025-6253HIGH7.5The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in ...
CVE-2025-5391HIGH8.1The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-42976HIGH8.1SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when subm...
CVE-2025-42951HIGH8.8Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of...
CVE-2025-55158HIGH8.8Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tu...
CVE-2025-55157HIGH8.8Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tu...
CVE-2025-55156HIGH7.8pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the paramete...
CVE-2025-55012HIGH8.5Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Re...
CVE-2025-25235HIGH8.6Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG...
CVE-2025-54878HIGH8.6CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-40920HIGH8.6Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID...
CVE-2025-7677HIGH8.2A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is d...
CVE-2025-54525HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-54463HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-52931HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-44004HIGH7.2Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance whic...
CVE-2025-25231HIGH7.5Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga...
CVE-2025-8859HIGH8.8A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionali...
CVE-2025-8863HIGH7YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
CVE-2025-8862HIGH7YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag config...
CVE-2025-8846HIGH7.8A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser....
CVE-2025-8845HIGH7.8A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the fi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now