2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59181 | MEDIUM | 4.8 | 0.3% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio... |
| CVE-2025-59180 | MEDIUM | 5.1 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s... |
| CVE-2025-59178 | MEDIUM | 4.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera... |
| CVE-2025-59177 | MEDIUM | 6.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi... |
| CVE-2025-59172 | HIGH | 8.5 | 0.2% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln... |
| CVE-2025-15662 | HIGH | 8.6 | — | Jul 27, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl... |
| CVE-2025-71408 | HIGH | 8.5 | 0.2% | Jul 24, 2026 | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m... |
| CVE-2025-9205 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.... |
| CVE-2025-71389 | CRITICAL | 10 | — | Jul 23, 2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio... |
| CVE-2025-68081 | MEDIUM | 5.9 | — | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |
| CVE-2025-60835 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. |
| CVE-2025-50330 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute... |
| CVE-2025-50329 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec... |
| CVE-2025-50327 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi... |
| CVE-2025-50325 | MEDIUM | 5.4 | 0.3% | Jul 22, 2026 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa... |
| CVE-2025-50324 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman... |
| CVE-2025-44090 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted... |
| CVE-2025-44089 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr... |
| CVE-2025-13146 | MEDIUM | 6.5 | 0.5% | Jul 22, 2026 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a... |
| CVE-2025-68640 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T... |
| CVE-2025-66390 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ... |
| CVE-2025-71398 | HIGH | 7.6 | 0.3% | Jul 18, 2026 | SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n... |
| CVE-2025-71397 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi... |
| CVE-2025-71396 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em... |
| CVE-2025-71395 | MEDIUM | 6.5 | 0.2% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now