2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9223HIGH8.8Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection v...
CVE-2025-11862HIGH8.4A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and de...
CVE-2025-11697HIGH8.9A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability a...
CVE-2025-11696HIGH8.9A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. ...
CVE-2025-11085HIGH8.6A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in t...
CVE-2025-11084HIGH7.6A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a val...
CVE-2025-10161HIGH7.3Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on ...
CVE-2025-12846HIGH8.8The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a...
CVE-2025-10714HIGH8.4AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala...
CVE-2025-11855HIGH7.5The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportReques...
CVE-2025-11307HIGH8.8The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJA...
CVE-2025-12637HIGH8.8The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f...
CVE-2025-11521HIGH8.1The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to i...
CVE-2025-11451HIGH7.5The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i...
CVE-2025-11168HIGH8.8The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5...
CVE-2025-42940HIGH7.5SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 da...
CVE-2025-64522HIGH7.6Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where ...
CVE-2025-64519HIGH8.8TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including ...
CVE-2025-63678HIGH7.2An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage...
CVE-2025-11578HIGH7.2A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise...
CVE-2025-64518HIGH7.5The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida...
CVE-2025-64512HIGH7.8Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documen...
CVE-2025-64509HIGH7.5Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope...
CVE-2025-64508HIGH7.5Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli strea...
CVE-2025-64507HIGH7.8Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now