2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13999HIGH7.2The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S...
CVE-2025-13008HIGH8.6An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and ...
CVE-2025-13307HIGH7.2The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic....
CVE-2025-14939HIGH7.2A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the...
CVE-2025-52692HIGH8.8Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially craft...
CVE-2025-14909HIGH8.1A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of...
CVE-2025-13941HIGH8.8A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installat...
CVE-2025-14908HIGH8.1A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file je...
CVE-2025-14900HIGH7.2A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown functi...
CVE-2025-14899HIGH7.2A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the f...
CVE-2025-11774HIGH8.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software...
CVE-2025-14898HIGH7.2A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of ...
CVE-2025-14897HIGH7.2A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown functi...
CVE-2025-64677HIGH8.2Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience all...
CVE-2025-64676HIGH7.2'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
CVE-2025-64663HIGH8.8Custom Question Answering Elevation of Privilege Vulnerability
CVE-2025-34452HIGH8.7Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-si...
CVE-2025-34451HIGH7.8rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflo...
CVE-2025-34450HIGH7.8merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vu...
CVE-2025-67653HIGH7.5Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence o...
CVE-2025-63951HIGH7.5An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project thro...
CVE-2025-63950HIGH7.5An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through co...
CVE-2025-62004HIGH7.7BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local,...
CVE-2025-62003HIGH7.7BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connect...
CVE-2025-62002HIGH8.1BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now