2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-22282HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keksdieb ez Form C...
CVE-2025-2243HIGH7.3A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input...
CVE-2025-1865HIGH8.5The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges...
CVE-2025-3229HIGH7.2A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vuln...
CVE-2025-3105HIGH8.8The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privil...
CVE-2025-3215HIGH8.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this...
CVE-2025-3086HIGH7.1Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous ...
CVE-2025-32111HIGH8.7The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-cred...
CVE-2025-2780HIGH8.8The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing...
CVE-2025-3211HIGH7.5A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affect...
CVE-2025-2317HIGH7.5The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend para...
CVE-2025-2270HIGH8.1The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion i...
CVE-2025-3210HIGH7.5A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected...
CVE-2025-3208HIGH7.5A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Aff...
CVE-2025-3197HIGH7.3Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index...
CVE-2025-3194HIGH7.7Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attacke...
CVE-2025-3192HIGH8.2Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl...
CVE-2025-2075HIGH8.8The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to ...
CVE-2025-3207HIGH7.5A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a...
CVE-2025-3206HIGH7.5A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerab...
CVE-2025-3205HIGH8.8A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an un...
CVE-2025-29815HIGH7.6Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2025-25000HIGH8.8Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2025-30370HIGH7.4jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Gi...
CVE-2025-3177HIGH8.1A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now