2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27423HIGH7.1Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing an...
CVE-2025-27422HIGH7.5FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker regis...
CVE-2025-27421HIGH7.5Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in t...
CVE-2025-25301HIGH7.5Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query par...
CVE-2025-0678HIGH7.8A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled pa...
CVE-2025-0289HIGH7.8Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not...
CVE-2025-0288HIGH7.8Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by t...
CVE-2025-0286HIGH8.4Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is cau...
CVE-2025-0285HIGH7.8Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is c...
CVE-2025-27419HIGH7.5WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS...
CVE-2025-25185HIGH7.5GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not prope...
CVE-2025-1801HIGH8.1A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concu...
CVE-2025-1125HIGH7.8When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesyste...
CVE-2025-0689HIGH7.8When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to alloc...
CVE-2025-27279HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lynk Flashfader fl...
CVE-2025-27278HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Ghedini AcuG...
CVE-2025-27275HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO ...
CVE-2025-27271HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alberto Cocchiara ...
CVE-2025-27269HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anton Aleksandrov ...
CVE-2025-27264HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-27263HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creativeitem Docto...
CVE-2025-26999HIGH8.8Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communiti...
CVE-2025-26988HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al...
CVE-2025-26967HIGH8.8Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allo...
CVE-2025-26914HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Insp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now