2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49487MEDIUM6.8An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could h...
CVE-2025-49158HIGH7.8An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to esc...
CVE-2025-49157HIGH7.8A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalat...
CVE-2025-49156HIGH7.8A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privil...
CVE-2025-49155HIGH8.8An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacke...
CVE-2025-49154HIGH7.8An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allo...
CVE-2025-34511HIGH8.8Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through vers...
CVE-2025-34510HIGH8.8Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10...
CVE-2025-34509HIGH7.5Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 1...
CVE-2025-49220CRITICAL9.8An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authenticat...
CVE-2025-49219CRITICAL9.8An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentica...
CVE-2025-47867CRITICAL9.8A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an atta...
CVE-2025-47866HIGH7.5An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att...
CVE-2025-47865CRITICAL9.8A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker...
CVE-2025-33122HIGH7.5IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in I...
CVE-2025-45880MEDIUM6.1A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows a...
CVE-2025-45878MEDIUM6.1A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers t...
CVE-2025-45879MEDIUM6.1A cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers t...
CVE-2025-6199LOW3.3A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompressio...
CVE-2025-6196MEDIUM5.5A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when ope...
CVE-2025-4754LOW2.3Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This v...
CVE-2025-49882MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer Cube...
CVE-2025-49881MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon...
CVE-2025-49880MEDIUM4.3Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured ...
CVE-2025-49879HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho litho all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now