2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-4960HIGH7.8The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca...
CVE-2025-4521HIGH8.8The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala...
CVE-2025-15041HIGH7.2The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-14452HIGH7.2The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param...
CVE-2025-13603HIGH8.8The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i...
CVE-2025-12975HIGH7.2The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst...
CVE-2025-12845HIGH8.8The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ...
CVE-2025-12821HIGH8.8The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is...
CVE-2025-12707HIGH7.5The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version...
CVE-2025-11754HIGH7.5The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2025-1272HIGH7.7The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis...
CVE-2025-70064HIGH8.8PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient...
CVE-2025-70151HIGH8.8code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestr...
CVE-2025-70148HIGH7.5Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allo...
CVE-2025-70147HIGH7.5Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all...
CVE-2025-71234HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_...
CVE-2025-71231HIGH7.1In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty...
CVE-2025-61982HIGH7.8An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A ...
CVE-2025-60038HIGH8.8A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the...
CVE-2025-60037HIGH8.8A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the...
CVE-2025-60036HIGH8.8A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions ...
CVE-2025-60035HIGH8.8A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions...
CVE-2025-59920HIGH8.6When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If...
CVE-2025-33253HIGH7.3NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user ...
CVE-2025-33252HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now