2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26477HIGH8.8Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with re...
CVE-2025-2903HIGH8.5An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Lo...
CVE-2025-3294HIGH7.2The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all ver...
CVE-2025-43715HIGH8.1Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM dur...
CVE-2025-43708HIGH7.5VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMa...
CVE-2025-1290HIGH8.1A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4...
CVE-2025-2073HIGH8.8Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with...
CVE-2025-1568HIGH8.8Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker...
CVE-2025-1566HIGH7.5DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose p...
CVE-2025-31478HIGH8.2Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely...
CVE-2025-25230HIGH7.8Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Clie...
CVE-2025-3728HIGH7.8A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability a...
CVE-2025-3620HIGH8.8Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-3619HIGH8.8Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potential...
CVE-2025-28072HIGH7.5PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.
CVE-2025-39472HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Req...
CVE-2025-32872HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32871HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32870HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32869HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32868HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32867HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32866HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32865HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32864HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now