2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2268HIGH7.5The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted re...
CVE-2025-29776HIGH8.7Azle is a WebAssembly runtime for TypeScript and JavaScript on ICP. Calling `setTimer` in Azle versions `0.27.0`, `0.28....
CVE-2025-27594HIGH7.5The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is tra...
CVE-2025-2221HIGH7.5The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all ve...
CVE-2025-2289HIGH8.8The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability ...
CVE-2025-2103HIGH8.8The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2025-1764HIGH7.5The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2025-0952HIGH8.1The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of...
CVE-2025-2056HIGH7.5The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versio...
CVE-2025-24855HIGH7.8numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can ...
CVE-2025-2230HIGH8.5A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authenticati...
CVE-2025-2229HIGH8.5A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across ...
CVE-2025-25598HIGH8.8Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers...
CVE-2025-24053HIGH7.2Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2025-2284HIGH7.5A denial-of-service vulnerability exists in the "GetWebLoginCredentials" function in "Sante PACS Server.exe".
CVE-2025-2265HIGH7.8The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and s...
CVE-2025-2264HIGH7.5A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attac...
CVE-2025-2081HIGH8.7Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to a...
CVE-2025-2079HIGH8.7Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard code...
CVE-2025-29773HIGH7.8Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as ...
CVE-2025-27107HIGH8.6Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft us...
CVE-2025-1652HIGH7.8A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A...
CVE-2025-1651HIGH7.8A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A...
CVE-2025-1650HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnera...
CVE-2025-1649HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now