2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-22628HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision Filled...
CVE-2025-30358HIGH8.1Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mes...
CVE-2025-30067HIGH7.2Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to ...
CVE-2025-2854HIGH8.8A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulner...
CVE-2025-29487HIGH7.5An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Serv...
CVE-2025-29484HIGH7.5An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Serv...
CVE-2025-22658HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Listings for Appfolio Listings for Appfolio listings-for-appfolio all...
CVE-2025-22652HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kendysond Payment ...
CVE-2025-21887HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ovl: fix UAF in ovl_dentry_update_reval by moving d...
CVE-2025-21883HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ice: Fix deinitializing VF in error path If ice_en...
CVE-2025-21879HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free on inode when scanning ro...
CVE-2025-25100HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in victoracano Cazamba cazamba allows Reflected XSS.This issue affects C...
CVE-2025-25086HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Secret Meta facebook-secret-meta allows Reflected XSS.Thi...
CVE-2025-21869HIGH7.8In the Linux kernel, the following vulnerability has been resolved: powerpc/code-patching: Disable KASAN report during ...
CVE-2025-21867HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf, test_run: Fix use-after-free issue in eth_skb_...
CVE-2025-2847HIGH8.8A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affe...
CVE-2025-2242HIGH8.8An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to...
CVE-2025-31141HIGH7.5In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
CVE-2025-30921HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software...
CVE-2025-30919HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Store Locator Widgets Store Locator Widget store-locator-widget allow...
CVE-2025-30895HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently...
CVE-2025-30891HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30890HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30879HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moreconvert Team M...
CVE-2025-30871HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now