2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41267HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41266HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41265HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-11262HIGH7.2The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all...
CVE-2025-11993HIGH8.8The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve...
CVE-2025-69600HIGH7.8Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execut...
CVE-2025-70103HIGH7.3Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function i...
CVE-2025-71306HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ima: Fix stack-out-of-bounds in is_bprm_creds_for_e...
CVE-2025-3633HIGH8.2IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable...
CVE-2025-52747HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox -...
CVE-2025-30028HIGH8.6A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2025-22741HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Fr...
CVE-2025-14713HIGH7.5An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0...
CVE-2025-41670HIGH8.7A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating co...
CVE-2025-41669HIGH8.8The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloade...
CVE-2025-46284HIGH7A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An...
CVE-2025-43306HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta...
CVE-2025-14361HIGH7.1Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly...
CVE-2025-36221HIGH7.5IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default pas...
CVE-2025-36126HIGH7.6IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to store...
CVE-2025-11482HIGH8.7An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating Syst...
CVE-2025-45145HIGH7.5Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attac...
CVE-2025-32749HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2025-32747HIGH7.8Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged...
CVE-2025-26483HIGH8.2Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now