2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41370HIGH8.8A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The...
CVE-2025-54939HIGH7.5LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
CVE-2025-8435HIGH7.3A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by thi...
CVE-2025-7725HIGH7.2The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str...
CVE-2025-7443HIGH8.1The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript p...
CVE-2025-8434HIGH7.3A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is a...
CVE-2025-48071HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-45768HIGH7pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length i...
CVE-2025-50572HIGH8.8Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into...
CVE-2025-45770HIGH7jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths a...
CVE-2025-26064HIGH7.3A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb...
CVE-2025-54833HIGH7.5OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protec...
CVE-2025-51503HIGH7.6A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts int...
CVE-2025-52203HIGH7.6A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability res...
CVE-2025-50850HIGH8.6An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such a...
CVE-2025-29556HIGH7.3ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions...
CVE-2025-52289HIGH8A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg...
CVE-2025-50849HIGH8CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling ...
CVE-2025-34146HIGH7A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitra...
CVE-2025-8213HIGH7.2The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien...
CVE-2025-8382HIGH8.8A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected ...
CVE-2025-8381HIGH8.8A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This...
CVE-2025-8379HIGH7.2A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an ...
CVE-2025-41688HIGH7.2A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the ...
CVE-2025-2813HIGH7.5An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http servi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now