2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8671HIGH7.5A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architect...
CVE-2025-48989HIGH7.5Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack...
CVE-2025-55280MEDIUM5.2This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plai...
CVE-2025-55279MEDIUM6.9This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. A...
CVE-2025-54465MEDIUM6.8This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the...
CVE-2025-54464HIGH7This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device f...
CVE-2025-8916MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on...
CVE-2025-8914HIGH7.5Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote at...
CVE-2025-8913CRITICAL9.8Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re...
CVE-2025-8912HIGH8.7Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated...
CVE-2025-8911MEDIUM6.1Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen...
CVE-2025-8910MEDIUM6.1Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen...
CVE-2025-8909HIGH7.1Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attacker...
CVE-2025-55345HIGH8.8Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file o...
CVE-2025-8762MEDIUM6.8A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the comp...
CVE-2025-8761HIGH7.7A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the co...
CVE-2025-8760CRITICAL9.8A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co...
CVE-2025-6184HIGH8.8The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection ...
CVE-2025-6715CRITICAL9.8The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes...
CVE-2025-7384CRITICAL9.8The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ...
CVE-2025-8891MEDIUM4.3The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to m...
CVE-2025-8491MEDIUM4.3The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-0818MEDIUM6.5Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various vers...
CVE-2025-8901HIGH8.8Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds...
CVE-2025-8882HIGH8.8Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now