2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66578HIGH7.5xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent...
CVE-2025-66507HIGH7.51Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauth...
CVE-2025-66271HIGH8.4Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr...
CVE-2025-63076HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-63074HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-63062HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-63036HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-63030HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Reques...
CVE-2025-63003HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-62093HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image...
CVE-2025-61075HIGH8.1Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authent...
CVE-2025-5471HIGH7.8Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affe...
CVE-2025-5470HIGH7.3Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects ...
CVE-2025-5469HIGH7.3Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue aff...
CVE-2025-59030HIGH7.5An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
CVE-2025-49351HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored...
CVE-2025-49347HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sI...
CVE-2025-49341HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This is...
CVE-2025-42878HIGH8.2SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unau...
CVE-2025-42877HIGH7.5SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploi...
CVE-2025-42876HIGH7.1Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authent...
CVE-2025-42874HIGH7.9SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrar...
CVE-2025-41752HIGH7.1An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user...
CVE-2025-41751HIGH7.1An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated use...
CVE-2025-41750HIGH7.1An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now