2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66578 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent... |
| CVE-2025-66507 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauth... |
| CVE-2025-66271 | HIGH | 8.4 | 0.1% | Dec 9, 2025 | Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr... |
| CVE-2025-63076 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63074 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63062 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63036 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63030 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Reques... |
| CVE-2025-63003 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62093 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image... |
| CVE-2025-61075 | HIGH | 8.1 | 0.5% | Dec 9, 2025 | Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authent... |
| CVE-2025-5471 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affe... |
| CVE-2025-5470 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects ... |
| CVE-2025-5469 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue aff... |
| CVE-2025-59030 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. |
| CVE-2025-49351 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored... |
| CVE-2025-49347 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sI... |
| CVE-2025-49341 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This is... |
| CVE-2025-42878 | HIGH | 8.2 | 0.3% | Dec 9, 2025 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unau... |
| CVE-2025-42877 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploi... |
| CVE-2025-42876 | HIGH | 7.1 | 0.3% | Dec 9, 2025 | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authent... |
| CVE-2025-42874 | HIGH | 7.9 | 0.4% | Dec 9, 2025 | SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrar... |
| CVE-2025-41752 | HIGH | 7.1 | 8.2% | Dec 9, 2025 | An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user... |
| CVE-2025-41751 | HIGH | 7.1 | 8.2% | Dec 9, 2025 | An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated use... |
| CVE-2025-41750 | HIGH | 7.1 | 8.4% | Dec 9, 2025 | An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now