2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31044HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE...
CVE-2025-68764HIGH7.8In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noex...
CVE-2025-68761HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hfs: fix potential use after free in hfs_correct_ne...
CVE-2025-68753HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l...
CVE-2025-5965HIGH7.2In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp...
CVE-2025-66518HIGH8.8Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses...
CVE-2025-15240HIGH8.8QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut...
CVE-2025-15239HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate...
CVE-2025-15238HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate...
CVE-2025-15235HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing auth...
CVE-2025-15462HIGH8.8A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/C...
CVE-2025-15461HIGH8.8A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/fo...
CVE-2025-15460HIGH8.8A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpC...
CVE-2025-15459HIGH8.8A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of...
CVE-2025-14124HIGH8.6The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat...
CVE-2025-15456HIGH7.5A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-...
CVE-2025-15443HIGH7.2A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr...
CVE-2025-15442HIGH7.2A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor...
CVE-2025-3660HIGH8.2Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows auth...
CVE-2025-3646HIGH8.2Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unau...
CVE-2025-64124HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene...
CVE-2025-64120HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene...
CVE-2025-69415HIGH7.1In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a...
CVE-2025-69414HIGH7.1Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit...
CVE-2025-67160HIGH7.5An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now