2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61740HIGH7.2Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-ser...
CVE-2025-26379HIGH7.2Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
CVE-2025-14018HIGH7.3Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating ...
CVE-2025-14273HIGH8.3Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab...
CVE-2025-61739HIGH7.2Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.
CVE-2025-12514HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon...
CVE-2025-11540HIGH7.5Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files withi...
CVE-2025-59301HIGH7.5Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.
CVE-2025-15015HIGH8.7Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote at...
CVE-2025-15009HIGH8.8A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExten...
CVE-2025-15004HIGH8.8A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php...
CVE-2025-15003HIGH7.2A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php....
CVE-2025-14995HIGH8.8A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIp...
CVE-2025-14994HIGH8.8A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the fi...
CVE-2025-14855HIGH7.2The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver...
CVE-2025-14800HIGH8.1The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type...
CVE-2025-14993HIGH8.8A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg...
CVE-2025-9343HIGH7.2The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-68644HIGH7.4Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed b...
CVE-2025-14992HIGH8.8A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the...
CVE-2025-14071HIGH7.5The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2025-12980HIGH7.5The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor...
CVE-2025-34290HIGH8.5Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili...
CVE-2025-7782HIGH7.6The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due...
CVE-2025-14591HIGH7.5In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now