2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26753HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast L...
CVE-2025-26752HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast L...
CVE-2025-26751HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Alph...
CVE-2025-1674HIGH8.2A lack of input validation allows for out of bounds reads caused by malicious or malformed packets.
CVE-2025-1673HIGH8.2A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of s...
CVE-2025-1648HIGH7.5The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and inclu...
CVE-2025-22210HIGH7.2A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (...
CVE-2025-1646HIGH7.3A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unkno...
CVE-2025-1643HIGH8.8A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some un...
CVE-2025-1642HIGH7.5A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects...
CVE-2025-26525HIGH8.6Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is ava...
CVE-2025-27133HIGH8.8WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-26200HIGH7.2SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_re...
CVE-2025-22495HIGH8.4An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. ...
CVE-2025-26803HIGH7.5The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a ...
CVE-2025-27355HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Nicolas GRILLET Woocommerce – Loi Hamon loi-hamon allows Stored XSS.T...
CVE-2025-27352HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wumii team 无觅相关文章插...
CVE-2025-27332HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown al...
CVE-2025-27321HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This iss...
CVE-2025-27312HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jenst WP Sitemap w...
CVE-2025-27301HIGH7.2Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-man...
CVE-2025-27300HIGH7.2Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affect...
CVE-2025-27298HIGH8.3Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection....
CVE-2025-27297HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in guelben Bravo Sear...
CVE-2025-27296HIGH7.2Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue rev...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now