2025 CVE Vulnerabilities

45,173 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3898HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou...
CVE-2025-3116HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou...
CVE-2025-3112HIGH7.1CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated...
CVE-2025-27819HIGH7.5In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Co...
CVE-2025-27818HIGH8.8A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the clus...
CVE-2025-27817HIGH7.5A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients a...
CVE-2025-4954HIGH8.8The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenti...
CVE-2025-4840HIGH7.5The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter b...
CVE-2025-5952HIGH7.3A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the f...
CVE-2025-5935HIGH7.5A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is...
CVE-2025-5934HIGH8.8A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function...
CVE-2025-5912HIGH8.8A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the f...
CVE-2025-4601HIGH8.8The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, ...
CVE-2025-4387HIGH8.8The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missi...
CVE-2025-5911HIGH8.8A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this ...
CVE-2025-5910HIGH8.8A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by ...
CVE-2025-5909HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected ...
CVE-2025-5908HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This...
CVE-2025-5907HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability af...
CVE-2025-42995HIGH7.5SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read acce...
CVE-2025-42994HIGH7.5SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory rea...
CVE-2025-42983HIGH8.5SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, pot...
CVE-2025-42982HIGH8.8SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control ...
CVE-2025-42977HIGH7.6SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input pa...
CVE-2025-23192HIGH7.6SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now