2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-30076HIGH7.7Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl repo...
CVE-2025-30074HIGH7.8Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation t...
CVE-2025-27281HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In ...
CVE-2025-26978HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fs-code FS Poster ...
CVE-2025-26976HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino Privat...
CVE-2025-26972HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateCo...
CVE-2025-26969HIGH8.3Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8...
CVE-2025-26961HIGH8.6Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Prop...
CVE-2025-26921HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-...
CVE-2025-26886HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress Publi...
CVE-2025-26556HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zzmaster WP AntiDD...
CVE-2025-26555HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thorsten Ott Debug...
CVE-2025-26554HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicola Mustone WP ...
CVE-2025-26553HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spring Devs Pre Or...
CVE-2025-26548HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kdmurray Random Im...
CVE-2025-23744HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dvs11 Random Posts...
CVE-2025-2025HIGH7.5The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data ...
CVE-2025-30066HIGH8.6tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr...
CVE-2025-1657HIGH8.8The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2025-1653HIGH8.8The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all ver...
CVE-2025-2310HIGH7.8A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the...
CVE-2025-2309HIGH7.8A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__b...
CVE-2025-2308HIGH7.8A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_...
CVE-2025-29387HIGH7.1In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerabili...
CVE-2025-25871HIGH8An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now