2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49390HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christophrado Cook...
CVE-2025-49386HIGH8.8Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows...
CVE-2025-48330HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48290HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48090HIGH8.1Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File...
CVE-2025-48085HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affec...
CVE-2025-48083HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This iss...
CVE-2025-48078HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issu...
CVE-2025-48077HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issu...
CVE-2025-39468HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39467HIGH8.1Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This is...
CVE-2025-39466HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39463HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31029HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail re...
CVE-2025-28953HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart ...
CVE-2025-12556HIGH8.8An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary cod...
CVE-2025-37735HIGH7Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being ...
CVE-2025-11956HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-9338HIGH7.3A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability...
CVE-2025-64171HIGH8.7MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n...
CVE-2025-55278HIGH8.1Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep...
CVE-2025-12779HIGH8.8Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,...
CVE-2025-63417HIGH7.2A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authe...
CVE-2025-12745HIGH7.8A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_a...
CVE-2025-11093HIGH7.2An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now