2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1912HIGH7.6The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server...
CVE-2025-2257HIGH7.2The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo...
CVE-2025-2009HIGH7.2The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all v...
CVE-2025-1514HIGH7.3The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unaut...
CVE-2025-29789HIGH7.5OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-27835HIGH7.8An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicod...
CVE-2025-27834HIGH7.8An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function...
CVE-2025-27833HIGH7.8An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/...
CVE-2025-27830HIGH7.8An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBl...
CVE-2025-25374HIGH7.5In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the lau...
CVE-2025-25372HIGH7.5NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memo...
CVE-2025-25371HIGH7.5NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any ar...
CVE-2025-30118HIGH7.5An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses...
CVE-2025-30567HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Pa...
CVE-2025-30214HIGH7.5Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could l...
CVE-2025-30213HIGH8.8Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to creat...
CVE-2025-30212HIGH7.5Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework...
CVE-2025-2532HIGH7.8Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2025-2531HIGH7.8Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2025-2530HIGH7.8Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-27147HIGH8.2The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNM...
CVE-2025-29635HIGH7.2A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar...
CVE-2025-22230HIGH7.8VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious act...
CVE-2025-1445HIGH8.7A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiat...
CVE-2025-2757HIGH8.8A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now