2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27277HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v...
CVE-2025-27276HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows ...
CVE-2025-27272HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-25279HIGH7.5Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate boa...
CVE-2025-1412HIGH8.8Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to ...
CVE-2025-1606HIGH7.5A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerab...
CVE-2025-22632HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalsoft WooComme...
CVE-2025-22631HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vbout Marketing Au...
CVE-2025-1594HIGH8.8A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_searc...
CVE-2025-1590HIGH7.2A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an un...
CVE-2025-1587HIGH7.8A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This i...
CVE-2025-1578HIGH7.5A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This af...
CVE-2025-27012HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce ...
CVE-2025-26774HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Respons...
CVE-2025-26760HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26757HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26756HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic t...
CVE-2025-0957HIGH7.2The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a...
CVE-2025-21704HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size be...
CVE-2025-27109HIGH7.3solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions...
CVE-2025-27106HIGH8.8binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-...
CVE-2025-27104HIGH7.5vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the i...
CVE-2025-26622HIGH7.5vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate ...
CVE-2025-25282HIGH8.1RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authentic...
CVE-2025-25769HIGH8Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/Use...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now