2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-39482HIGH8.8Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control...
CVE-2025-32310HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quick...
CVE-2025-32307HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chame...
CVE-2025-32306HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio...
CVE-2025-32301HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Count...
CVE-2025-32290HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick...
CVE-2025-32287HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Respo...
CVE-2025-31928HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multi...
CVE-2025-31926HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick...
CVE-2025-31922HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Sto...
CVE-2025-31641HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberS...
CVE-2025-31640HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic...
CVE-2025-31637HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT...
CVE-2025-4782HIGH8.8A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This ...
CVE-2025-4781HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an...
CVE-2025-4778HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vul...
CVE-2025-4600HIGH7.5A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling...
CVE-2025-4211HIGH7.3Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib modu...
CVE-2025-4777HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This a...
CVE-2025-40629HIGH8.7PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform di...
CVE-2025-37890HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class w...
CVE-2025-2305HIGH8.6A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthentica...
CVE-2025-4770HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. Th...
CVE-2025-4769HIGH7.3A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknow...
CVE-2025-1975HIGH7.5A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now