2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1003HIGH8.5A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass ...
CVE-2025-24958HIGH8.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24902HIGH8.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24901HIGH8.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24371HIGH7.1CometBFT is a distributed, Byzantine fault-tolerant, deterministic state machine replication engine. In the `blocksync` ...
CVE-2025-24962HIGH8.8reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands v...
CVE-2025-24960HIGH8.7Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user...
CVE-2025-24899HIGH7.5reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where ...
CVE-2025-22918HIGH7.5Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the us...
CVE-2025-25181HIGH7.5A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to ex...
CVE-2025-25064HIGH8.8SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10...
CVE-2025-24781HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoar...
CVE-2025-24707HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga...
CVE-2025-24684HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media...
CVE-2025-24676HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Cust...
CVE-2025-24661HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking...
CVE-2025-24660HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple ...
CVE-2025-24656HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna ...
CVE-2025-24646HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc XML for A...
CVE-2025-24631HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email A...
CVE-2025-24630HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MantraBrain Sikshy...
CVE-2025-24629HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpgear Import Exce...
CVE-2025-24620HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hkharpreetkumar1 A...
CVE-2025-24605HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi...
CVE-2025-24576HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now