2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49845HIGH7.5Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers...
CVE-2025-25905HIGH7.1Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web ...
CVE-2025-6610HIGH7.2A vulnerability was found in itsourcecode Employee Management System up to 1.0. It has been classified as critical. This...
CVE-2025-6609HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-6608HIGH8.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected b...
CVE-2025-6607HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affecte...
CVE-2025-6606HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Th...
CVE-2025-6605HIGH8.8A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability ...
CVE-2025-6604HIGH8.8A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects a...
CVE-2025-5927HIGH7.5The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path vali...
CVE-2025-49797HIGH8.5Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary ...
CVE-2025-41256HIGH7.4Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), sinc...
CVE-2025-41255HIGH8Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), un...
CVE-2025-36004HIGH8.8IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Fa...
CVE-2025-0966HIGH7.6IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL s...
CVE-2025-6583HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This af...
CVE-2025-6582HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Af...
CVE-2025-6581HIGH8.8A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vu...
CVE-2025-52888HIGH7.5Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entit...
CVE-2025-52882HIGH8.8Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium)...
CVE-2025-49852HIGH8.7ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability...
CVE-2025-6570HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected...
CVE-2025-44531HIGH7.5An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a...
CVE-2025-23265HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i...
CVE-2025-23264HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now