2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27233MEDIUM5.7Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex...
CVE-2025-10267MEDIUM6.9NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote at...
CVE-2025-10266CRITICAL9.8NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i...
CVE-2025-10265HIGH8.8Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att...
CVE-2025-7448HIGH8.6Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the ...
CVE-2025-10264CRITICAL10Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthentic...
CVE-2025-21043CRITICAL9.8Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitra...
CVE-2025-21042CRITICAL9.8Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra...
CVE-2025-9086HIGH7.51. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak...
CVE-2025-8575HIGH7.2The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i...
CVE-2025-8280MEDIUM5.8The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before...
CVE-2025-7337MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3...
CVE-2025-6769MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-6454HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18...
CVE-2025-58781MEDIUM6.3WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor en...
CVE-2025-3650LOW3.5The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes o...
CVE-2025-2256HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-1250MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-10291HIGH8.8A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th...
CVE-2025-10148MEDIUM5.3curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Ins...
CVE-2025-10288MEDIUM5.5A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is a...
CVE-2025-10287LOW3.1A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element...
CVE-2025-10094MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-9881MEDIUM6.1The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-9880MEDIUM6.1The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now