2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68764HIGH7.8In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noex...
CVE-2025-68761HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hfs: fix potential use after free in hfs_correct_ne...
CVE-2025-68753HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l...
CVE-2025-5965HIGH7.2In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp...
CVE-2025-66518HIGH8.8Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses...
CVE-2025-15240HIGH8.8QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut...
CVE-2025-15239HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate...
CVE-2025-15238HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate...
CVE-2025-15235HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing auth...
CVE-2025-15462HIGH8.8A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/C...
CVE-2025-15461HIGH8.8A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/fo...
CVE-2025-15460HIGH8.8A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpC...
CVE-2025-15459HIGH8.8A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of...
CVE-2025-14124HIGH8.6The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat...
CVE-2025-15456HIGH7.5A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-...
CVE-2025-15443HIGH7.2A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr...
CVE-2025-15442HIGH7.2A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor...
CVE-2025-3660HIGH8.2Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows auth...
CVE-2025-3646HIGH8.2Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unau...
CVE-2025-64124HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene...
CVE-2025-64120HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene...
CVE-2025-69415HIGH7.1In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a...
CVE-2025-69414HIGH7.1Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit...
CVE-2025-67160HIGH7.5An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers...
CVE-2025-67159HIGH7.5Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now