2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5439HIGH8.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-3260HIGH8.3A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard a...
CVE-2025-5455HIGH8.4An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkRe...
CVE-2025-5438HIGH8.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-5435HIGH7.3A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unkno...
CVE-2025-5113HIGH8.6The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and ...
CVE-2025-0358HIGH8.8During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi...
CVE-2025-0324HIGH8.8The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain admini...
CVE-2025-5434HIGH7.3A vulnerability was found in Aem Solutions CMS up to 1.0. It has been classified as critical. This affects an unknown pa...
CVE-2025-4010HIGH8.6The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoin...
CVE-2025-5431HIGH8.8A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of th...
CVE-2025-49113HIGH8.8Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the ...
CVE-2025-25179HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to ...
CVE-2025-5406HIGH8.8A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952...
CVE-2025-5404HIGH7.5A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c673...
CVE-2025-5403HIGH8.8A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6...
CVE-2025-33005HIGH8.8IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated u...
CVE-2025-5381HIGH7.2A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function down...
CVE-2025-4857HIGH7.2The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9...
CVE-2025-5375HIGH8.8A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critica...
CVE-2025-5374HIGH8.8A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affec...
CVE-2025-5373HIGH8.8A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulner...
CVE-2025-4672HIGH8.8The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization plac...
CVE-2025-4103HIGH8.8The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_aj...
CVE-2025-5368HIGH8.8A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now