2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-64353HIGH8.8Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P...
CVE-2025-58149HIGH7.5When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the...
CVE-2025-58148HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-58147HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-12115HIGH7.5The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi...
CVE-2025-11843HIGH8.8Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun...
CVE-2025-62232HIGH7.5Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f...
CVE-2025-30189HIGH7.4When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached ...
CVE-2025-30188HIGH7.5Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform...
CVE-2025-10897HIGH8.6The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi...
CVE-2025-7846HIGH8.8The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-63675HIGH8.8cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt...
CVE-2025-54763HIGH8.6FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user...
CVE-2025-8849HIGH7.5LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api...
CVE-2025-6176HIGH7.5Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio...
CVE-2025-52664HIGH8.8SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo...
CVE-2025-52663HIGH7.3A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention...
CVE-2025-48984HIGH8.8A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2025-48982HIGH7.8This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator ...
CVE-2025-34298HIGH8.8Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change ...
CVE-2025-34287HIGH7.8Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical...
CVE-2025-34286HIGH7.2Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C...
CVE-2025-34284HIGH8.8Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio...
CVE-2025-34280HIGH7.2Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function...
CVE-2025-34134HIGH7.2Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now