2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8420HIGH8.1Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code ...
CVE-2025-54635HIGH7.5Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of...
CVE-2025-54630HIGH7.5:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulne...
CVE-2025-54628HIGH7.5Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of thi...
CVE-2025-54627HIGH8.8Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-8654HIGH8.8Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-a...
CVE-2025-8653HIGH8.8Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-7036HIGH7.5The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all vers...
CVE-2025-54622HIGH7.4Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnera...
CVE-2025-54610HIGH7.5Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54609HIGH7.5Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54607HIGH7.5Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54606HIGH7.1Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will ...
CVE-2025-54655HIGH7.8Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect...
CVE-2025-54884HIGH8.7Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be...
CVE-2025-54879HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration...
CVE-2025-54872HIGH8.7onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd...
CVE-2025-54801HIGH7.5Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParse...
CVE-2025-53534HIGH7.7RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obta...
CVE-2025-51628HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and be...
CVE-2025-7674HIGH7.1Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input da...
CVE-2025-54254HIGH8.6Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Refe...
CVE-2025-43978HIGH7.4Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vul...
CVE-2025-43979HIGH7.4An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute ar...
CVE-2025-29745HIGH7.5A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now