2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11002HIGH7.87-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-9290MEDIUM5.9An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption d...
CVE-2025-67652MEDIUM6.1An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges...
CVE-2025-55705CRITICAL9.8This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg...
CVE-2025-54816CRITICAL9.8This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho...
CVE-2025-53968HIGH7.5This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An...
CVE-2025-25051MEDIUM6.1An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to netwo...
CVE-2025-9289MEDIUM4.7A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sani...
CVE-2025-14751HIGH8.7A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m...
CVE-2025-14750HIGH8.7The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally con...
CVE-2025-22234MEDIUM5.3The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvi...
CVE-2025-68609MEDIUM6.6A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality o...
CVE-2025-66428HIGH8.8An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
CVE-2025-56590CRITICAL9.8An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could ...
CVE-2025-70899MEDIUM6.5PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative form...
CVE-2025-69828CRITICAL10File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker ...
CVE-2025-69321HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand S...
CVE-2025-69320HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand M...
CVE-2025-69319HIGH7.5Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-...
CVE-2025-69318HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hossni Mubarak Job...
CVE-2025-69317HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarS...
CVE-2025-69316HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn...
CVE-2025-69315MEDIUM6.5Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit...
CVE-2025-69314HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69313HIGH7.5Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now