2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12859HIGH7.2A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_...
CVE-2025-34299CRITICAL9.8Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This fl...
CVE-2025-12857CRITICAL9.8A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow...
CVE-2025-12856CRITICAL9.8A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /...
CVE-2025-12855CRITICAL9.8A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi...
CVE-2025-12854LOW3.7A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill o...
CVE-2025-12853CRITICAL9.8A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele...
CVE-2025-10968HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna...
CVE-2025-10870CRITICAL9.3SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete datab...
CVE-2025-46413MEDIUM5.3Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W...
CVE-2025-10966MEDIUM4.3curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host...
CVE-2025-64346MEDIUM6archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to fe...
CVE-2025-64343HIGH7.8(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 ...
CVE-2025-64339MEDIUM5.4ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature i...
CVE-2025-12527MEDIUM4.3The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili...
CVE-2025-12520MEDIUM4The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ...
CVE-2025-64338CRITICAL9ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular use...
CVE-2025-64336MEDIUM5.4ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is v...
CVE-2025-64329MEDIUM5.5containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro...
CVE-2025-4522MEDIUM6.5The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct ...
CVE-2025-4519HIGH8.8The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala...
CVE-2025-12352CRITICAL9.8The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-64328HIGH7.2FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov...
CVE-2025-64323MEDIUM5.3kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack a...
CVE-2025-64187MEDIUM4.4OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now