2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8756HIGH8.8A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulne...
CVE-2025-4581HIGH8.6Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-55009HIGH7.1The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthK...
CVE-2025-55008HIGH7.1The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKi...
CVE-2025-55006HIGH8.8Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image u...
CVE-2025-54996HIGH7.2OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-54888HIGH8.7Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4....
CVE-2025-54417HIGH8.8Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a v...
CVE-2025-8744HIGH7.3A vulnerability classified as critical was found in CesiumLab Web up to 4.0. This vulnerability affects unknown code of ...
CVE-2025-46709HIGH7.5Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern...
CVE-2025-4796HIGH8.8The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i...
CVE-2025-52914HIGH8.8A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a...
CVE-2025-8393HIGH8.5A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts se...
CVE-2025-53520HIGH8.8The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or insta...
CVE-2025-50465HIGH8.8OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-8355HIGH7.5In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker ...
CVE-2025-52586HIGH7.5The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryp...
CVE-2025-36119HIGH8.8IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certifi...
CVE-2025-8088HIGH8.8A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by...
CVE-2025-8748HIGH8.8MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP reques...
CVE-2025-8708HIGH7.5A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the...
CVE-2025-8706HIGH8.8A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as criti...
CVE-2025-8705HIGH8.8A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving Syst...
CVE-2025-8704HIGH8.8A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving...
CVE-2025-8703HIGH8.8A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now