2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3872HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-...
CVE-2025-3776HIGH8.3The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions ...
CVE-2025-3607HIGH8.8The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2025-3300HIGH7.2The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all version...
CVE-2025-3101HIGH8.8The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2025-3058HIGH8.8The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es...
CVE-2025-1908HIGH7.7An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potential...
CVE-2025-0639HIGH7.5An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions fro...
CVE-2025-41395HIGH7.5Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by th...
CVE-2025-3761HIGH8.8The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions u...
CVE-2025-35965HIGH7.5Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity o...
CVE-2025-2558HIGH8.6The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to ...
CVE-2025-46417HIGH7.5The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltra...
CVE-2025-27580HIGH7.5NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that de...
CVE-2025-46397HIGH7.8A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spli...
CVE-2025-32818HIGH7.5A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated...
CVE-2025-28169HIGH8.1BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the ma...
CVE-2025-3904HIGH7.3Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.
CVE-2025-3903HIGH7.3Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
CVE-2025-2773HIGH7.2BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability all...
CVE-2025-2769HIGH7.8Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc...
CVE-2025-2768HIGH7.8Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc...
CVE-2025-2765HIGH8.8CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability al...
CVE-2025-2764HIGH8CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vul...
CVE-2025-2762HIGH7.8CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local at...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now