2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-32365HIGH7.1Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in...
CVE-2025-3303HIGH7.5A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0....
CVE-2025-32360HIGH8.1In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared articl...
CVE-2025-32359HIGH8.8In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor a...
CVE-2025-3299HIGH7.3A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this iss...
CVE-2025-2933HIGH8.8The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lea...
CVE-2025-0810HIGH7.5The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-1500HIGH8IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be e...
CVE-2025-3267HIGH8.8A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknow...
CVE-2025-3259HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the funct...
CVE-2025-3256HIGH7.5A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unkn...
CVE-2025-3255HIGH7.5A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerabilit...
CVE-2025-32280HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Re...
CVE-2025-32220HIGH8.8Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorr...
CVE-2025-32204HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rocketelements Spl...
CVE-2025-32203HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in manu225 Falling th...
CVE-2025-32159HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32157HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32156HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32155HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32154HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32153HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32152HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32151HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32150HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now