2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-45614HIGH7.5Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information...
CVE-2025-45613HIGH7.5Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati...
CVE-2025-45610HIGH7.5Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen...
CVE-2025-45609HIGH7.5Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf...
CVE-2025-45608HIGH7.5Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens...
CVE-2025-4279HIGH8.8The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-46559HIGH7.5Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m...
CVE-2025-4282HIGH8.8A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. Th...
CVE-2025-4096HIGH8.8Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit he...
CVE-2025-4050HIGH8.8Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced ...
CVE-2025-45237HIGH7.5Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file c...
CVE-2025-45242HIGH7.7Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method ...
CVE-2025-0217HIGH7.8BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A loc...
CVE-2025-45322HIGH8.8kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the...
CVE-2025-45321HIGH8.8kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.ph...
CVE-2025-28062HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allow...
CVE-2025-27920HIGH8.8Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us...
CVE-2025-4272HIGH7.3A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is...
CVE-2025-4270HIGH7.5A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown f...
CVE-2025-4267HIGH7.2A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. Th...
CVE-2025-4260HIGH8.3A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is...
CVE-2025-20671HIGH7In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of priv...
CVE-2025-20668HIGH7.8In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2025-20667HIGH7.5In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote informat...
CVE-2025-20666HIGH7.5In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now