2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-30571HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in STEdb Corp. STEdb ...
CVE-2025-30570HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AliRezaMohammadi د...
CVE-2025-30569HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featur...
CVE-2025-30565HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager banner-manager allows Stored XSS.This issue a...
CVE-2025-30564HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpwox Custom Script Integration custom-script-integration allows Stor...
CVE-2025-30561HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Henrique Mouta CAS Maestro cas-maestro allows Stored XSS.This issue a...
CVE-2025-30560HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah jQuery Dropdown Menu jquery-drop-down-menu-plugin allows S...
CVE-2025-30558HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in EnzoCostantini55 ANAC XML Render anac-xml-render allows Stored XSS.Th...
CVE-2025-30555HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in iiiryan WordPres 同步微博 wp2wb allows Stored XSS.This issue affects Word...
CVE-2025-30552HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Donald Gilbert WordPress Admin Bar Improved wordpress-admin-bar-impro...
CVE-2025-30550HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r callphoner allows Stored XSS.This issue affects...
CVE-2025-30525HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ProfitShare.ro WP ...
CVE-2025-30523HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marcel-NL Super Si...
CVE-2025-30522HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design cf7-material-design allow...
CVE-2025-0835HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
CVE-2025-0478HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to a...
CVE-2025-2672HIGH7.5A vulnerability was found in code-projects Payroll Management System 1.0. It has been rated as critical. This issue affe...
CVE-2025-2664HIGH7.2A vulnerability was found in CodeZips Hospital Management System 1.0 and classified as critical. Affected by this issue ...
CVE-2025-2662HIGH8.8A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affecte...
CVE-2025-29795HIGH7.8Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a...
CVE-2025-2652HIGH7.5A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro...
CVE-2025-27553HIGH7.5Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'res...
CVE-2025-2624HIGH7.5A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-2622HIGH8.8A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRun...
CVE-2025-2186HIGH7.5The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now