2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-15281HIGH7.5Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cau...
CVE-2025-14377HIGH8.8A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext...
CVE-2025-14376HIGH8.6A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secre...
CVE-2025-14027HIGH8.7Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various ...
CVE-2025-11743HIGH7.1A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open ...
CVE-2025-14977HIGH8.1The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2025-52659HIGH7.5HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit...
CVE-2025-68616HIGH7.5WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro...
CVE-2025-61684HIGH7.5Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a...
CVE-2025-11044HIGH8.9An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Run...
CVE-2025-29847HIGH7.5A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and ...
CVE-2025-15539HIGH7.5A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notificati...
CVE-2025-15538HIGH7.8A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerabili...
CVE-2025-15534HIGH7.8A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of t...
CVE-2025-15533HIGH7.8A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageF...
CVE-2025-15532HIGH7.5A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component ...
CVE-2025-15530HIGH7.5A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_fo...
CVE-2025-14478HIGH7.5The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, ...
CVE-2025-15529HIGH7.5A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_...
CVE-2025-15528HIGH7.5A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the...
CVE-2025-68924HIGH7.5In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a...
CVE-2025-62291HIGH8.1In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted ...
CVE-2025-48647HIGH7.8In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope...
CVE-2025-15032HIGH7.4Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof ...
CVE-2025-31510HIGH7.2In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now