2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-46232HIGH8.8Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configure...
CVE-2025-46231HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter...
CVE-2025-3519HIGH7An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Ev...
CVE-2025-26413HIGH7.5Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a...
CVE-2025-2594HIGH8.1The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when ...
CVE-2025-3616HIGH8.8The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m...
CVE-2025-1731HIGH7.8An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware ...
CVE-2025-3854HIGH8.6A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function E...
CVE-2025-32956HIGH8ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ...
CVE-2025-27086HIGH8.1A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
CVE-2025-23174HIGH7.5CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-43922HIGH8.1The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca...
CVE-2025-3857HIGH8.7When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check t...
CVE-2025-2298HIGH8.4An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the...
CVE-2025-43972HIGH7.5An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec pars...
CVE-2025-43971HIGH7.5An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value...
CVE-2025-43967HIGH7.5libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a gri...
CVE-2025-43966HIGH7.5libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.
CVE-2025-43929HIGH7.8open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that ma...
CVE-2025-43920HIGH8.1GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated ...
CVE-2025-43919HIGH7.5GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ dir...
CVE-2025-3820HIGH8.8A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this ...
CVE-2025-43917HIGH8.2In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst...
CVE-2025-3817HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue ...
CVE-2025-3816HIGH7.2A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now