2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41225HIGH8.8The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to creat...
CVE-2025-26086HIGH7.5An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parame...
CVE-2025-47941HIGH7.2TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS an...
CVE-2025-47940HIGH7.2TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4....
CVE-2025-41231HIGH7.3VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Fo...
CVE-2025-41230HIGH7.5VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port ...
CVE-2025-41229HIGH8.2VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 ...
CVE-2025-30193HIGH7.5In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP conn...
CVE-2025-37892HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob(...
CVE-2025-2929HIGH7.1The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-4971HIGH8.5Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execu...
CVE-2025-3079HIGH8.7A passback vulnerability which relates to office/small office multifunction printers and laser printers.
CVE-2025-3078HIGH8.7A passback vulnerability which relates to production printers and office multifunction printers.
CVE-2025-1308HIGH8.4A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.
CVE-2025-47949HIGH7.5samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to ver...
CVE-2025-47944HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1...
CVE-2025-47935HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource ...
CVE-2025-39393HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital ...
CVE-2025-39392HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apa...
CVE-2025-39372HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPres...
CVE-2025-39366HIGH8.8Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
CVE-2025-39365HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProje...
CVE-2025-39357HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital ...
CVE-2025-39355HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Servic...
CVE-2025-39352HIGH8.2Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now