2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1123HIGH7.2The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-5106HIGH7.3A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the...
CVE-2025-5105HIGH7.3A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknow...
CVE-2025-41407HIGH8.3Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
CVE-2025-3893HIGH8.6While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this a...
CVE-2025-36527HIGH8.3Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
CVE-2025-5100HIGH8A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory cor...
CVE-2025-48371HIGH8.8OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfg...
CVE-2025-47181HIGH8.8Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a...
CVE-2025-48372HIGH7.3Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time...
CVE-2025-48075HIGH7.5Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber...
CVE-2025-30172HIGH8.9Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This...
CVE-2025-47780HIGH7.8Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste...
CVE-2025-46715HIGH7.8Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve...
CVE-2025-45472HIGH8.8Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer clou...
CVE-2025-33137HIGH8.8IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau...
CVE-2025-33136HIGH8.8IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau...
CVE-2025-45468HIGH8.8Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the cust...
CVE-2025-5080HIGH8.8A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFil...
CVE-2025-5024HIGH7.4A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated atta...
CVE-2025-45471HIGH8.8Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cl...
CVE-2025-32813HIGH7.2An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
CVE-2025-4979HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor...
CVE-2025-46714HIGH7.8Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve...
CVE-2025-46713HIGH7.8Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now