2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-53007HIGH8.9arduino-esp32 provides an Arduino core for the ESP32. Versions prior to 3.3.0-RC1 and 3.2.1 contain a HTTP Response Spli...
CVE-2025-52887HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http head...
CVE-2025-51672HIGH8A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. T...
CVE-2025-6710HIGH7.5MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON input...
CVE-2025-6709HIGH7.5The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values ...
CVE-2025-6706HIGH8.8An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior...
CVE-2025-48921HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affec...
CVE-2025-6693HIGH8.5A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_dev...
CVE-2025-6562HIGH8.8Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allow...
CVE-2025-5966HIGH8.1Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by f...
CVE-2025-5366HIGH8.1Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read...
CVE-2025-3771HIGH7.1A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin loc...
CVE-2025-5459HIGH8.8A user with specific node group editing permissions and a specially crafted class parameter could be used to execute com...
CVE-2025-37101HIGH8.7A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability cou...
CVE-2025-2938HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-6624HIGH7.2Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through ...
CVE-2025-5590HIGH8.8The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all...
CVE-2025-6667HIGH8.8A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is s...
CVE-2025-6661HIGH7.8PDF-XChange Editor App Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attac...
CVE-2025-6660HIGH7.8PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a...
CVE-2025-6659HIGH7.8PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-6654HIGH7.8PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-6651HIGH7.8PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-6647HIGH7.8PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-6645HIGH7.8PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now