2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-39491HIGH8.1Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through r...
CVE-2025-39482HIGH8.8Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control...
CVE-2025-32310HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quick...
CVE-2025-32307HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chame...
CVE-2025-32306HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio...
CVE-2025-32301HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Count...
CVE-2025-32290HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick...
CVE-2025-32287HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Respo...
CVE-2025-31928HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multi...
CVE-2025-31926HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick...
CVE-2025-31922HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Sto...
CVE-2025-31641HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberS...
CVE-2025-31640HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic...
CVE-2025-31637HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT...
CVE-2025-4782HIGH8.8A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This ...
CVE-2025-4781HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an...
CVE-2025-4778HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vul...
CVE-2025-4600HIGH7.5A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling...
CVE-2025-4211HIGH7.3Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib modu...
CVE-2025-4777HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This a...
CVE-2025-40629HIGH8.7PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform di...
CVE-2025-37890HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class w...
CVE-2025-2305HIGH8.6A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthentica...
CVE-2025-4770HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. Th...
CVE-2025-4769HIGH7.3A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now