2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24853HIGH7.5A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to...
CVE-2025-54757HIGH8Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malici...
CVE-2025-54752HIGH8Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malform...
CVE-2025-46359HIGH8.6A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator ma...
CVE-2025-53558HIGH8.8ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o...
CVE-2025-7847HIGH8.8The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the re...
CVE-2025-8348HIGH7.5A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability ...
CVE-2025-49083HIGH7.2CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to v...
CVE-2025-54581HIGH7.5vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-cont...
CVE-2025-53022HIGH8.6TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validat...
CVE-2025-52187HIGH8.2GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_for...
CVE-2025-50777HIGH7.8The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Acc...
CVE-2025-36609HIGH7.8Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low p...
CVE-2025-45620HIGH8.1An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
CVE-2025-36611HIGH7.8Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Befo...
CVE-2025-8312HIGH7.1Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its...
CVE-2025-54433HIGH7.2Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, ...
CVE-2025-53944HIGH7.7AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6...
CVE-2025-8323HIGH8.8The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload ...
CVE-2025-8322HIGH8.8The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to ...
CVE-2025-8292HIGH8.8Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit...
CVE-2025-8320HIGH8.8Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerabi...
CVE-2025-4425HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4423HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4422HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now