2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10157HIGH7.8A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remot...
CVE-2025-0546MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Ren...
CVE-2025-10591MEDIUM5.4A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet...
CVE-2025-10590MEDIUM6.1A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of th...
CVE-2025-10156CRITICAL9.8An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 pickles...
CVE-2025-10155HIGH7.8An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0...
CVE-2025-0420MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof...
CVE-2025-59458CRITICAL9.8In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54...
CVE-2025-59457HIGH7.7In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
CVE-2025-59456MEDIUM5.5In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
CVE-2025-59455MEDIUM4.2In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
CVE-2025-0419MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor...
CVE-2025-9242CRITICAL9.8An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac...
CVE-2025-9972CRITICAL9.8Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability,...
CVE-2025-9971CRITICAL9.8Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability...
CVE-2025-9565MEDIUM6.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newslet...
CVE-2025-9450HIGH7.8A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release...
CVE-2025-9449HIGH7.8A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS De...
CVE-2025-9447HIGH7.8An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR...
CVE-2025-9216HIGH8.8The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-9215MEDIUM6.5The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-9203MEDIUM6.4The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl...
CVE-2025-10058HIGH8.1The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion du...
CVE-2025-10057HIGH8.8The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in a...
CVE-2025-10042HIGH7.5The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now