2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5131HIGH7.2A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the...
CVE-2025-5130HIGH7.2A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function up...
CVE-2025-5126HIGH8.8A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the...
CVE-2025-4602HIGH7.5The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u...
CVE-2025-48754HIGH7.5In the memory_pages crate 0.1.0 for Rust, division by zero can occur.
CVE-2025-43860HIGH7.6OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-...
CVE-2025-32794HIGH7.6OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-...
CVE-2025-24917HIGH7.8In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could ...
CVE-2025-24916HIGH7.8When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions pr...
CVE-2025-48292HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48286HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restau...
CVE-2025-48273HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Porta...
CVE-2025-48245HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick C...
CVE-2025-48241HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verg...
CVE-2025-47690HIGH8.8Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allow...
CVE-2025-47680HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup...
CVE-2025-47678HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit Funn...
CVE-2025-47673HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc...
CVE-2025-47672HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47671HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LETSCMS MLM Softwa...
CVE-2025-47670HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47660HIGH8.8Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This...
CVE-2025-47658HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketi...
CVE-2025-47631HIGH8.8Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This is...
CVE-2025-47618HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mortgage Calculato...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now