2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31490HIGH7.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2025-3587HIGH8.8A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects...
CVE-2025-3585HIGH8.8A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the fil...
CVE-2025-22373HIGH8.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SicommNet B...
CVE-2025-32914HIGH7.4A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read...
CVE-2025-32913HIGH7.5A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL p...
CVE-2025-32908HIGH7.5A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :...
CVE-2025-32906HIGH7.5A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. ...
CVE-2025-3566HIGH7.3A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the ...
CVE-2025-3565HIGH7.2A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affect...
CVE-2025-3563HIGH7.2A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of ...
CVE-2025-27009HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows S...
CVE-2025-24859HIGH8.8A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not prope...
CVE-2025-3556HIGH8.1A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vul...
CVE-2025-31344HIGH7.3Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program fil...
CVE-2025-3555HIGH8.1A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an ...
CVE-2025-30516HIGH7.5Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor c...
CVE-2025-2563HIGH8.1The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when ...
CVE-2025-3572HIGH7.5SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to pr...
CVE-2025-3546HIGH8.6A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. ...
CVE-2025-3545HIGH8.6A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. ...
CVE-2025-3544HIGH8.6A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 a...
CVE-2025-3543HIGH8.6A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classif...
CVE-2025-3542HIGH8.6A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R0...
CVE-2025-3541HIGH8.6A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Mag...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now