2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1971HIGH7.2The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up ...
CVE-2025-1970HIGH7.6The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi...
CVE-2025-2303HIGH8.8The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in al...
CVE-2025-0724HIGH8.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in al...
CVE-2025-30204HIGH7.5golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, t...
CVE-2025-2608HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown ...
CVE-2025-2602HIGH8.8A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as cri...
CVE-2025-2601HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management Sy...
CVE-2025-25035HIGH7.3Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 al...
CVE-2025-30349HIGH7.2Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take...
CVE-2025-29230HIGH8.6Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. Th...
CVE-2025-30157HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy'...
CVE-2025-29641HIGH7.3Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' ...
CVE-2025-24915HIGH7.8When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not ...
CVE-2025-2592HIGH8.8A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue ...
CVE-2025-25274HIGH8.8Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived ...
CVE-2025-25068HIGH8.8Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin...
CVE-2025-30347HIGH7.5Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read fo...
CVE-2025-2581HIGH7.5A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the fu...
CVE-2025-2585HIGH8.8EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular p...
CVE-2025-29814HIGH8.8Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
CVE-2025-29807HIGH8.8Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
CVE-2025-30334HIGH7.1In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash...
CVE-2025-25758HIGH7.5An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBack...
CVE-2025-30160HIGH7.5Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker ca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now