2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-29556HIGH7.3ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions...
CVE-2025-8408CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unk...
CVE-2025-52289HIGH8A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg...
CVE-2025-51569MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. Th...
CVE-2025-50849HIGH8CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling ...
CVE-2025-50475CRITICAL9.8An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated a...
CVE-2025-50270MEDIUM6.1A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remot...
CVE-2025-34146HIGH7A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitra...
CVE-2025-29557MEDIUM5.4ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where user...
CVE-2025-8407CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue af...
CVE-2025-7738MEDIUM4.4A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub...
CVE-2025-54589MEDIUM6.1Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, use...
CVE-2025-8213HIGH7.2The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien...
CVE-2025-8401MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2025-8382HIGH8.8A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected ...
CVE-2025-8381HIGH8.8A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This...
CVE-2025-8151MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, ...
CVE-2025-8068MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of ...
CVE-2025-8380MEDIUM5.4A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability...
CVE-2025-8379HIGH7.2A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an ...
CVE-2025-8378CRITICAL9.8A vulnerability was found in Campcodes Online Hotel Reservation System 1.0. It has been rated as critical. Affected by t...
CVE-2025-8376CRITICAL9.8A vulnerability classified as critical has been found in code-projects Vehicle Management 1.0. Affected is an unknown fu...
CVE-2025-41688HIGH7.2A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the ...
CVE-2025-40980MEDIUM5.1A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due ...
CVE-2025-2813HIGH7.5An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http servi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now