2025 CVE Vulnerabilities

45,180 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5276HIGH7.4Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the...
CVE-2025-48926HIGH7.5The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, ...
CVE-2025-48925HIGH7.5The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then...
CVE-2025-32801HIGH7.8Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea a...
CVE-2025-4134HIGH7.3Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof o...
CVE-2025-48734HIGH8.8Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2....
CVE-2025-45997HIGH8.6Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can uploa...
CVE-2025-5299HIGH7.3A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. Thi...
CVE-2025-1753HIGH7.8LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the impro...
CVE-2025-5287HIGH7.5The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio...
CVE-2025-25251HIGH7.8An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 th...
CVE-2025-22252HIGH7.2A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager v...
CVE-2025-4800HIGH8.8The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati...
CVE-2025-5280HIGH8.8Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap ...
CVE-2025-5279HIGH7When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the drive...
CVE-2025-5222HIGH7A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'su...
CVE-2025-5063HIGH8.8Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit h...
CVE-2025-45529HIGH7.1An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbit...
CVE-2025-23247HIGH7.8NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the len...
CVE-2025-27700HIGH8.4There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of ...
CVE-2025-5247HIGH7.3A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function ...
CVE-2025-5245HIGH7.8A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_s...
CVE-2025-48383HIGH8.2Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses li...
CVE-2025-48798HIGH7.3A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special...
CVE-2025-48797HIGH7.3A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now