2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8653HIGH8.8Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-7036HIGH7.5The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all vers...
CVE-2025-54622HIGH7.4Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnera...
CVE-2025-54610HIGH7.5Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54609HIGH7.5Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54607HIGH7.5Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54606HIGH7.1Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will ...
CVE-2025-54655HIGH7.8Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect...
CVE-2025-54884HIGH8.7Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be...
CVE-2025-54879HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration...
CVE-2025-54872HIGH8.7onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd...
CVE-2025-54801HIGH7.5Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParse...
CVE-2025-53534HIGH7.7RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obta...
CVE-2025-51628HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and be...
CVE-2025-7674HIGH7.1Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input da...
CVE-2025-54254HIGH8.6Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Refe...
CVE-2025-43978HIGH7.4Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vul...
CVE-2025-43979HIGH7.4An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute ar...
CVE-2025-29745HIGH7.5A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser...
CVE-2025-7033HIGH7.8A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re...
CVE-2025-7032HIGH7.8A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re...
CVE-2025-7025HIGH7.8A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re...
CVE-2025-6207HIGH8.8The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2025-5061HIGH8.8The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2025-41698HIGH7.8A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now