2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41016HIGH8.7Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images...
CVE-2025-40212CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nf...
CVE-2025-12628MEDIUM6.3The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th...
CVE-2025-41729HIGH7.5An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denia...
CVE-2025-41087MEDIUM5.1Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not pro...
CVE-2025-12741HIGH7.7A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, ca...
CVE-2025-12740HIGH7.7A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML,...
CVE-2025-12739HIGH7.3An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would exe...
CVE-2025-13596LOW2.7A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Applicati...
CVE-2025-13588MEDIUM6.3A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun...
CVE-2025-13586HIGH7.2A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file...
CVE-2025-13585CRITICAL9.8A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of th...
CVE-2025-12629HIGH7.1The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-12569MEDIUM4.7The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before ...
CVE-2025-12394MEDIUM5.9The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur...
CVE-2025-7402HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In...
CVE-2025-13584LOW3.5A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the com...
CVE-2025-13583CRITICAL9.8A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /...
CVE-2025-13589MEDIUM5.1FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthentica...
CVE-2025-13582CRITICAL9.8A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functiona...
CVE-2025-13581HIGH8.8A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-13580HIGH8.8A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.ph...
CVE-2025-13579HIGH8.8A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php....
CVE-2025-13578CRITICAL9.8A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index....
CVE-2025-13577MEDIUM5.4A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the fil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now