2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59181MEDIUM4.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio...
CVE-2025-59180MEDIUM5.1Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s...
CVE-2025-59178MEDIUM4.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera...
CVE-2025-59177MEDIUM6.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi...
CVE-2025-59172HIGH8.5Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln...
CVE-2025-15662HIGH8.6The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl...
CVE-2025-71408HIGH8.5NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m...
CVE-2025-9205MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14....
CVE-2025-71389CRITICAL10Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio...
CVE-2025-68081MEDIUM5.9Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2025-60835HIGH7.8An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330HIGH8.8An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute...
CVE-2025-50329CRITICAL9.8An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec...
CVE-2025-50327HIGH8.8An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi...
CVE-2025-50325MEDIUM5.4BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa...
CVE-2025-50324HIGH8.8An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman...
CVE-2025-44090HIGH8.8An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted...
CVE-2025-44089HIGH8.8An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr...
CVE-2025-13146MEDIUM6.5The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a...
CVE-2025-68640MEDIUM5.3The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T...
CVE-2025-66390CRITICAL9.8In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ...
CVE-2025-71398HIGH7.6SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n...
CVE-2025-71397MEDIUM6.5SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi...
CVE-2025-71396MEDIUM6.5SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em...
CVE-2025-71395MEDIUM6.5SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now