2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-0182HIGH7.5A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue ar...
CVE-2025-1385HIGH7.5When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows ...
CVE-2025-22228HIGH7.4BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters ...
CVE-2025-1770HIGH8.8The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File In...
CVE-2025-27787HIGH7.5Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart....
CVE-2025-27785HIGH7.5Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `...
CVE-2025-27784HIGH7.5Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `...
CVE-2025-27777HIGH7.5Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `mod...
CVE-2025-2476HIGH8.8Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap co...
CVE-2025-27415HIGH7.5Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a ser...
CVE-2025-29924HIGH7.5XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get...
CVE-2025-30154HIGH8.6reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2...
CVE-2025-30153HIGH7.5kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/for...
CVE-2025-2324HIGH8.8Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP mo...
CVE-2025-1758HIGH8.8Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster...
CVE-2025-30236HIGH8.6Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skippin...
CVE-2025-1232HIGH8.8The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which co...
CVE-2025-30234HIGH8.3SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32...
CVE-2025-30140HIGH7.5An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It ...
CVE-2025-30142HIGH8.1An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address ver...
CVE-2025-30141HIGH7.5An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream....
CVE-2025-29907HIGH7.5jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage me...
CVE-2025-24801HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.p...
CVE-2025-26137HIGH7.5Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attac...
CVE-2025-27688HIGH7.8Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now