2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6002HIGH7.2An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated a...
CVE-2025-6001HIGH8.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasse...
CVE-2025-40915HIGH7Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of th...
CVE-2025-22874HIGH7.5Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. Th...
CVE-2025-49148HIGH7.3ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows u...
CVE-2025-48447HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgaller...
CVE-2025-48446HIGH8.8Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affec...
CVE-2025-48445HIGH8.8Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affe...
CVE-2025-4922HIGH8.1Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and...
CVE-2025-32711HIGH7.5Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2025-5687HIGH7.8A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects M...
CVE-2025-3302HIGH7.2The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ ...
CVE-2025-4315HIGH8.8The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all vers...
CVE-2025-41661HIGH8.8An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack o...
CVE-2025-29756HIGH8.3SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the us...
CVE-2025-5395HIGH8.8The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ...
CVE-2025-4799HIGH7.2The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the d...
CVE-2025-5959HIGH8.8Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside...
CVE-2025-5958HIGH8.8Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap c...
CVE-2025-4275HIGH7.8A vulnerability in the digital signature verification process does not properly validate variable attributes which allow...
CVE-2025-49091HIGH8.2KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme ...
CVE-2025-32717HIGH8.4Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-5985HIGH7.3A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this i...
CVE-2025-47849HIGH8.8A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do...
CVE-2025-47713HIGH8.8A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now