2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5878HIGH7.3A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Enc...
CVE-2025-6857HIGH7.8A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the funct...
CVE-2025-6856HIGH7.8A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_li...
CVE-2025-6855HIGH8.8A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This...
CVE-2025-6850HIGH8.8A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerabil...
CVE-2025-6848HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects ...
CVE-2025-6846HIGH7.3A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of...
CVE-2025-6842HIGH7.2A vulnerability was found in code-projects Product Inventory System 1.0 and classified as critical. This issue affects s...
CVE-2025-6841HIGH7.2A vulnerability has been found in code-projects Product Inventory System 1.0 and classified as critical. This vulnerabil...
CVE-2025-6829HIGH8.8A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as criti...
CVE-2025-6825HIGH8.8A vulnerability classified as critical was found in TOTOLINK A702R up to 4.0.0-B20230721.1521. Affected by this vulnerab...
CVE-2025-6824HIGH7.5A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown...
CVE-2025-6818HIGH7.8A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_prot...
CVE-2025-1991HIGH7.5IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an in...
CVE-2025-6755HIGH8.8The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path...
CVE-2025-6381HIGH8.8The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including...
CVE-2025-6379HIGH8.8The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2025-53098HIGH8.1Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stor...
CVE-2025-53097HIGH7.5Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent'...
CVE-2025-53094HIGH8.7ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In version...
CVE-2025-6772HIGH7.5A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the functi...
CVE-2025-53093HIGH8.6TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version ...
CVE-2025-6521HIGH7.6During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the...
CVE-2025-44557HIGH8.1A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypas...
CVE-2025-53339HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now