2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12183HIGH8.8Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service ...
CVE-2025-51735HIGH7.5CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-12638HIGH8Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin...
CVE-2025-13771HIGH7.1WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit ...
CVE-2025-13770HIGH7.1WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2025-13769HIGH7.1WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2025-13768HIGH8.8WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in...
CVE-2025-66384HIGH8.2app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela...
CVE-2025-64312HIGH7.5Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma...
CVE-2025-58311HIGH7.1UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availabili...
CVE-2025-64315HIGH7.1Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-58314HIGH7.1Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner...
CVE-2025-58309HIGH7.1Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w...
CVE-2025-66360HIGH8.8An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo...
CVE-2025-13757HIGH8.8SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025...
CVE-2025-13692HIGH7.2The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2025-59890HIGH7.3Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths ...
CVE-2025-13536HIGH8.8The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida...
CVE-2025-7820HIGH7.5The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including...
CVE-2025-13680HIGH8.8The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ...
CVE-2025-12758HIGH7.7Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe...
CVE-2025-66314HIGH7.5Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper...
CVE-2025-0658HIGH8.7A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev...
CVE-2025-0657HIGH8.8A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed...
CVE-2025-66035HIGH7.7Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now