2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6463HIGH8.8The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary ...
CVE-2025-6459HIGH8.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Reques...
CVE-2025-6437HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via...
CVE-2025-5817HIGH7.2The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2025-5339HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In...
CVE-2025-5014HIGH8.8The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff...
CVE-2025-4381HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via...
CVE-2025-36630HIGH7.1In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit...
CVE-2025-49741HIGH7.5No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a ...
CVE-2025-53107HIGH7.5@cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is ...
CVE-2025-53100HIGH8.6RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server i...
CVE-2025-45081HIGH8.8Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.
CVE-2025-34081HIGH7.5The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may cont...
CVE-2025-6297HIGH8.2It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a...
CVE-2025-53099HIGH7.5Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a ...
CVE-2025-37098HIGH7.5A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-34066HIGH8.3An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with...
CVE-2025-34059HIGH8.7An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username...
CVE-2025-34058HIGH8.7Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate ...
CVE-2025-6953HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an un...
CVE-2025-37097HIGH7.5A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
CVE-2025-36582HIGH7.5Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit...
CVE-2025-6940HIGH8.8A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability ...
CVE-2025-6939HIGH8.8A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown f...
CVE-2025-53095HIGH8.8Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now