2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71389CRITICAL10Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio...
CVE-2025-68081MEDIUM5.9Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2025-60835HIGH7.8An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330HIGH8.8An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute...
CVE-2025-50329CRITICAL9.8An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec...
CVE-2025-50327HIGH8.8An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi...
CVE-2025-50325MEDIUM5.4BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa...
CVE-2025-50324HIGH8.8An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman...
CVE-2025-44090HIGH8.8An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted...
CVE-2025-44089HIGH8.8An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr...
CVE-2025-13146MEDIUM6.5The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a...
CVE-2025-68640MEDIUM5.3The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T...
CVE-2025-66390CRITICAL9.8In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ...
CVE-2025-71398MEDIUM5.8SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n...
CVE-2025-71397HIGH7.1SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi...
CVE-2025-71396LOW2.3SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em...
CVE-2025-71395HIGH7.1SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ...
CVE-2025-71394LOW2.3SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut...
CVE-2025-71393MEDIUM6SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e...
CVE-2025-71392CRITICAL9.4SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the...
CVE-2025-71391HIGH7.1SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ...
CVE-2025-71390MEDIUM5.8SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains...
CVE-2025-51678HIGH7.5An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une...
CVE-2025-51677CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12...
CVE-2025-59866LOW3.3The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now