2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4523MEDIUM6.5The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized acc...
CVE-2025-8434HIGH7.3A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is a...
CVE-2025-8433MEDIUM5.4A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects...
CVE-2025-5947CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all ...
CVE-2025-54847Rejected reason: Not used
CVE-2025-54846Rejected reason: Not used
CVE-2025-54845Rejected reason: Not used
CVE-2025-54844Rejected reason: Not used
CVE-2025-54843Rejected reason: Not used
CVE-2025-54842Rejected reason: Not used
CVE-2025-54841Rejected reason: Not used
CVE-2025-54840Rejected reason: Not used
CVE-2025-54839Rejected reason: Not used
CVE-2025-54657Rejected reason: Not used
CVE-2025-53399MEDIUM6.9In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic of the media-relay core ...
CVE-2025-5954CRITICAL9.8The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver...
CVE-2025-8431CRITICAL9.8A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe...
CVE-2025-48073MEDIUM6.2OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-48072CRITICAL9.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-48071HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-45768HIGH7pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length i...
CVE-2025-23289MEDIUM5.5NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause ...
CVE-2025-8286CRITICAL9.3The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modi...
CVE-2025-50572HIGH8.8Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into...
CVE-2025-45770HIGH7jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now