2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7050HIGH7.2The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-54868HIGH7.5LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint ...
CVE-2025-54871HIGH7.8Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app...
CVE-2025-54870HIGH8.7VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules ...
CVE-2025-54803HIGH7.5js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype ...
CVE-2025-54780HIGH7.7The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2...
CVE-2025-53544HIGH7.5Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person...
CVE-2025-8530HIGH7.5A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue...
CVE-2025-46093HIGH8.8LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execut...
CVE-2025-27211HIGH7.5An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a mal...
CVE-2025-8527HIGH8.8A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown pr...
CVE-2025-51726HIGH8.4CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnera...
CVE-2025-53395HIGH7.7Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privile...
CVE-2025-53394HIGH7.7Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges vi...
CVE-2025-38741HIGH7.5Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote at...
CVE-2025-8518HIGH7.2A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function S...
CVE-2025-51534HIGH8.1A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers ...
CVE-2025-44963HIGH8.1RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded ...
CVE-2025-44961HIGH8.8In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided b...
CVE-2025-44960HIGH8.8RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
CVE-2025-44958HIGH7.5RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
CVE-2025-44957HIGH8.8Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea...
CVE-2025-44955HIGH8.8RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
CVE-2025-44643HIGH8.6Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R...
CVE-2025-30099HIGH7.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now