2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12497HIGH8.1The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version...
CVE-2025-10622HIGH8A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set...
CVE-2025-64151HIGH8.4Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A ...
CVE-2025-62225HIGH8.4Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use...
CVE-2025-12384HIGH8.6The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce...
CVE-2025-12139HIGH7.5The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv...
CVE-2025-21079HIGH8.1Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL ...
CVE-2025-21075HIGH7.5Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b...
CVE-2025-21074HIGH7.5Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bo...
CVE-2025-12197HIGH7.5The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15...
CVE-2025-64110HIGH7.5Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen...
CVE-2025-64109HIGH8.8Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta all...
CVE-2025-64108HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr...
CVE-2025-64107HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may ...
CVE-2025-64106HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor'...
CVE-2025-59595HIGH7.5CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12....
CVE-2025-62507HIGH8.8Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD...
CVE-2025-62369HIGH7.2Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con...
CVE-2025-56230HIGH7.5Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.
CVE-2025-54526HIGH8.4Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted pro...
CVE-2025-54496HIGH8.4A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which ma...
CVE-2025-32786HIGH7.5The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...
CVE-2025-49494HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, ...
CVE-2025-23358HIGH8.2NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path eleme...
CVE-2025-54334HIGH7.5An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now