2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-4823HIGH8.8A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Aff...
CVE-2025-4190HIGH7.2The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege us...
CVE-2025-3812HIGH8.1The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-1706HIGH7.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2025-4810HIGH8.8A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is ...
CVE-2025-4809HIGH8.8A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSaf...
CVE-2025-4808HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affe...
CVE-2025-4807HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. T...
CVE-2025-4802HIGH7.8Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker c...
CVE-2025-4806HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1....
CVE-2025-4795HIGH7.2A vulnerability classified as critical has been found in gongfuxiang schoolcms 2.3.1. This affects the function SaveInfo...
CVE-2025-4787HIGH8.8A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected ...
CVE-2025-4786HIGH8.8A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This i...
CVE-2025-48138HIGH8.8Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ...
CVE-2025-48136HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48134HIGH7.2Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection....
CVE-2025-48114HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger shayanweb-admin-fo...
CVE-2025-48112HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot ht...
CVE-2025-47693HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47567HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video...
CVE-2025-39537HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Bet...
CVE-2025-39507HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39493HIGH8.8Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Acce...
CVE-2025-39492HIGH7.5Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2 ...
CVE-2025-39491HIGH8.1Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through r...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now