2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49746HIGH8.8Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
CVE-2025-47995HIGH8.8Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
CVE-2025-54079HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54075HIGH8.3MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.1...
CVE-2025-54073HIGH7.5mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documenta...
CVE-2025-53945HIGH7apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prio...
CVE-2025-7788HIGH8.8A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability...
CVE-2025-7787HIGH8.8A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function ht...
CVE-2025-49486HIGH8.6A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicio...
CVE-2025-49485HIGH8.6A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute ar...
CVE-2025-49484HIGH8.7A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execut...
CVE-2025-6023HIGH7.6An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vuln...
CVE-2025-38349HIGH7.8In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still ...
CVE-2025-7438HIGH7.5The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid...
CVE-2025-6718HIGH8.8The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX...
CVE-2025-6813HIGH8.8The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi...
CVE-2025-3740HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up...
CVE-2025-7759HIGH8.8A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file mod...
CVE-2025-7758HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected b...
CVE-2025-7397HIGH7.1A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interfa...
CVE-2025-7755HIGH8.8A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects...
CVE-2025-7754HIGH7.5A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. This ...
CVE-2025-7433HIGH8.8A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and o...
CVE-2025-6249HIGH8.4An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with e...
CVE-2025-6248HIGH7.4A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sen...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now