2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-28170HIGH7.6Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with direct...
CVE-2025-28171MEDIUM6.5An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the ...
CVE-2025-51970HIGH7.7A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 du...
CVE-2025-50738CRITICAL9.8The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us...
CVE-2025-46059CRITICAL9.8langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component....
CVE-2025-28172MEDIUM6.5Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Att...
CVE-2025-52358MEDIUM6.3A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Lo...
CVE-2025-7458CRITICAL9.1An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attack...
CVE-2025-6505HIGH8.1Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipe...
CVE-2025-6504HIGH8.4In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-...
CVE-2025-6175HIGH7.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Sp...
CVE-2025-6060MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Softwa...
CVE-2025-54422MEDIUM5.5Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1....
CVE-2025-41241MEDIUM4.4VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and ha...
CVE-2025-40686MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40685MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40684MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40683MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40682CRITICAL9.8SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, creat...
CVE-2025-5587MEDIUM6.4The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in al...
CVE-2025-8216MEDIUM6.4The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in a...
CVE-2025-8196MEDIUM6.4The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cust...
CVE-2025-7689HIGH8.8The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf...
CVE-2025-6730MEDIUM4.3The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2025-6692MEDIUM6.4The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now