2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31904HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Reque...
CVE-2025-31828HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site R...
CVE-2025-31132HIGH8.1Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoi...
CVE-2025-31131HIGH7.5YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read ...
CVE-2025-28398HIGH7.1D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
CVE-2025-28395HIGH7.1D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
CVE-2025-3034HIGH8.1Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption a...
CVE-2025-3033HIGH7.7After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *...
CVE-2025-3032HIGH7.4Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. ...
CVE-2025-3030HIGH8.1Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs...
CVE-2025-3029HIGH7.3A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a poten...
CVE-2025-22231HIGH7.8VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative ...
CVE-2025-1660HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A...
CVE-2025-1659HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability....
CVE-2025-1658HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability....
CVE-2025-3083HIGH7.5Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur ...
CVE-2025-27130HIGH8.8Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnera...
CVE-2025-2891HIGH8.8The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-31415HIGH7.6Missing Authorization vulnerability in YayCommerce YayExtra yayextra allows Exploiting Incorrectly Configured Access Con...
CVE-2025-31074HIGH8.8Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This...
CVE-2025-31024HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Qui...
CVE-2025-31001HIGH7.5Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sen...
CVE-2025-30924HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Pri...
CVE-2025-30917HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham SKU Genera...
CVE-2025-30910HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions C...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now