2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13442CRITICAL9.8A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the func...
CVE-2025-13435HIGH8.1A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of ...
CVE-2025-13434HIGH7.5A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file H...
CVE-2025-13433HIGH7.3A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the...
CVE-2025-12778MEDIUM5.3The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-12502MEDIUM6.8The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2025-12414CRITICAL9.2An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email addr...
CVE-2025-11676HIGH7.1Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated...
CVE-2025-0645HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Lt...
CVE-2025-0643HIGH7.2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Comm...
CVE-2025-13424CRITICAL9.8A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file...
CVE-2025-13423HIGH7.2A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function ...
CVE-2025-13422CRITICAL9.8A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown ...
CVE-2025-4042Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-13421CRITICAL9.8A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown ...
CVE-2025-13420CRITICAL9.8A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown pro...
CVE-2025-13415MEDIUM5.4A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php...
CVE-2025-11884LOW2.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uC...
CVE-2025-11001HIGH7.87-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-63719HIGH7.3Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter use...
CVE-2025-63371HIGH7.5Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file p...
CVE-2025-58181MEDIUM5.3SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, al...
CVE-2025-47914MEDIUM5.3SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the progra...
CVE-2025-13412MEDIUM6.1A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn...
CVE-2025-13411CRITICAL9.8A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unk...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now