2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-29311HIGH7.5Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce att...
CVE-2025-2231HIGH7.8PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows re...
CVE-2025-2749HIGH7.2An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arb...
CVE-2025-30208HIGH7.5Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15,...
CVE-2025-30205HIGH7.6kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to ver...
CVE-2025-30112HIGH7.1On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP ...
CVE-2025-29778HIGH8Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyvern...
CVE-2025-0255HIGH7.2HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on t...
CVE-2025-2705HIGH7.3A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload ...
CVE-2025-30621HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator translator allows Stored XSS.This issue affects T...
CVE-2025-30620HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in coderscom WP Odoo Form Integrator wp-odoo-form-integrator allows Stor...
CVE-2025-30612HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mandegarweb Replace Default Words replace-default-words allows Stored...
CVE-2025-30608HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Anthony WordPress SQL Backup wordpress-sql-backup allows Stored XSS.T...
CVE-2025-30604HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jiangqie JiangQie ...
CVE-2025-30603HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in DEJAN CopyLink copy-link allows Stored XSS.This issue affects CopyLin...
CVE-2025-30602HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related P...
CVE-2025-30590HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dourou Flickr set ...
CVE-2025-30588HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ryan_xantoo Map Contact map-contact allows Stored XSS.This issue affe...
CVE-2025-30587HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in shawfactor LH OGP Meta lh-ogp-meta-tags allows Stored XSS.This issue ...
CVE-2025-30586HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in bbodine1 cTabs ctabs allows Stored XSS.This issue affects cTabs: from...
CVE-2025-30584HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in alphaomegaplugins AlphaOmega Captcha & Anti-Spam Filter alphaomega-ca...
CVE-2025-30583HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ProRankTracker Pro Rank Tracker proranktracker allows Stored XSS.This...
CVE-2025-30578HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored...
CVE-2025-30577HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows ...
CVE-2025-30572HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Igor Yavych Simple Rating simple-rating allows Stored XSS.This issue ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now