2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31117HIGH7.5OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band ...
CVE-2025-30005HIGH8.3Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of a...
CVE-2025-30004HIGH8.8Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for at...
CVE-2025-2794HIGH8.7An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, ...
CVE-2025-3002HIGH7.3A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue a...
CVE-2025-1449HIGH7.5A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion...
CVE-2025-2997HIGH8.8A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown fu...
CVE-2025-31625HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Usei...
CVE-2025-31623HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor richtexteditor allows Stored XSS.This...
CVE-2025-31617HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Gagan Deep Singh PostmarkApp Email Integrator postmarkapp-email-integ...
CVE-2025-31616HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress varnish-wp allows Cross Site Request For...
CVE-2025-31615HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in owenr88 Simple Con...
CVE-2025-31613HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Aboobacker. AB Google Map Travel ab-google-map-travel allows Cross S...
CVE-2025-31585HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in leadfox Leadfox for WordPress leadfox allows Cross Site Request Forge...
CVE-2025-31583HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL wp-copy-media-url allows Stored XSS.Th...
CVE-2025-31570HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wp-buy Related Posts Widget with Thumbnails advanced-css3-related-pos...
CVE-2025-31569HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wp-buy wordpress related Posts with thumbnails related-posts-list-gri...
CVE-2025-31566HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery rio-video-gallery allows Stored XSS.Thi...
CVE-2025-31547HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aphotrax Uptime Ro...
CVE-2025-31542HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auction...
CVE-2025-31526HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance P...
CVE-2025-2586HIGH7.5A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repea...
CVE-2025-3021HIGH8.7Path Traversal vulnerability in e-solutions e-management. This vulnerability could allow an attacker to access confident...
CVE-2025-23995HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow a...
CVE-2025-2985HIGH8.8A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now