2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66698HIGH8.6An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to var...
CVE-2025-65783CRITICAL9.8An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2....
CVE-2025-12548CRITICAL9A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe...
CVE-2025-55462MEDIUM6.5A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header ...
CVE-2025-36640HIGH8.8A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts whi...
CVE-2025-13447MEDIUM6.8OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker ...
CVE-2025-13444MEDIUM6.8OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker ...
CVE-2025-9435MEDIUM5.5Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
CVE-2025-9427HIGH8.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft W...
CVE-2025-14507MEDIUM5.3The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Expos...
CVE-2025-11669HIGH8.1Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versi...
CVE-2025-11250CRITICAL9.1Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper fi...
CVE-2025-13774HIGH8.8A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability ...
CVE-2025-59022HIGH8.1Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the T...
CVE-2025-59021MEDIUM6.4Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, crea...
CVE-2025-59020MEDIUM6.5By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO...
CVE-2025-14001MEDIUM5.4The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability ...
CVE-2025-40944HIGH8.7A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200M...
CVE-2025-40942HIGH7.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains...
CVE-2025-40805CRITICAL10Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe...
CVE-2025-41717HIGH8.8An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-up...
CVE-2025-14829CRITICAL9.1The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient ...
CVE-2025-10915CRITICAL9.8The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check...
CVE-2025-66177HIGH8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models....
CVE-2025-66176HIGH8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now