2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-69369HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68886HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58897HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58707HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58705HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58024HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53440HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53345HIGH8.8Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress ...
CVE-2025-52759HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Acco...
CVE-2025-59606HIGH7.8Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initi...
CVE-2025-59605HIGH7.8Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604HIGH7.8Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-48652HIGH7.8In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in...
CVE-2025-48649HIGH7.8In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass...
CVE-2025-48595HIGH8.4In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to ...
CVE-2025-48570HIGH7.8In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to...
CVE-2025-32348HIGH7.8In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead...
CVE-2025-26418HIGH7.8In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when ...
CVE-2025-22426HIGH7.8In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th...
CVE-2025-22424HIGH7.8In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul...
CVE-2025-70099HIGH7.5A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attacke...
CVE-2025-41281HIGH7.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41280HIGH7.8Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9....
CVE-2025-41279HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41278HIGH7.8Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R260114104...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now