2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10907HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte...
CVE-2025-63248HIGH7.5DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID...
CVE-2025-46364HIGH7.2Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI...
CVE-2025-45379HIGH8.4Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma...
CVE-2025-43990HIGH7.8Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerabilit...
CVE-2025-30479HIGH7.2Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma...
CVE-2025-20376HIGH7.2A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a...
CVE-2025-20375HIGH7.2A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a...
CVE-2025-20343HIGH7.5A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi...
CVE-2025-57130HIGH8.8An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au...
CVE-2025-64458HIGH7.5An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s...
CVE-2025-61084HIGH7.1MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h...
CVE-2025-46784HIGH7.5A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouver...
CVE-2025-46705HIGH7.5A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2....
CVE-2025-46404HIGH7.5A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert La...
CVE-2025-3125HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp...
CVE-2025-12497HIGH8.1The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version...
CVE-2025-10622HIGH8A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set...
CVE-2025-64151HIGH8.4Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A ...
CVE-2025-62225HIGH8.4Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use...
CVE-2025-12384HIGH8.6The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce...
CVE-2025-12139HIGH7.5The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv...
CVE-2025-21079HIGH8.1Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL ...
CVE-2025-21075HIGH7.5Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b...
CVE-2025-21074HIGH7.5Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now