2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3064HIGH8.8The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-3431HIGH7.5The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in ...
CVE-2025-31332HIGH7.1Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access...
CVE-2025-30014HIGH7.7SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could a...
CVE-2025-27428HIGH7.7Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using...
CVE-2025-23186HIGH8.5In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function...
CVE-2025-3413HIGH8.8A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified ...
CVE-2025-3410HIGH8.8A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code ...
CVE-2025-3409HIGH8.8A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_inclu...
CVE-2025-20948HIGH7.1Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged ...
CVE-2025-20946HIGH8.8Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prio...
CVE-2025-20944HIGH7.1Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read ...
CVE-2025-20936HIGH7.8Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to ...
CVE-2025-3408HIGH8.8A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the fu...
CVE-2025-3407HIGH8.8A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerabilit...
CVE-2025-3402HIGH7.5A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critic...
CVE-2025-32414HIGH7.5In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindi...
CVE-2025-2526HIGH8.8The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i...
CVE-2025-2525HIGH8.8The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_...
CVE-2025-32409HIGH8.1Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signe...
CVE-2025-0942HIGH8.6The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an...
CVE-2025-32034HIGH7.5The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th...
CVE-2025-32033HIGH7.5The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th...
CVE-2025-32032HIGH7.5The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th...
CVE-2025-32031HIGH7.5Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now