2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62790HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch...
CVE-2025-62789HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert...
CVE-2025-62788HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev...
CVE-2025-62787HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer ...
CVE-2025-61234HIGH7.5Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local networ...
CVE-2025-60595HIGH8.2SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.
CVE-2025-12479HIGH8.8Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-...
CVE-2025-62786HIGH8.1Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds...
CVE-2025-62785HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation ...
CVE-2025-61429HIGH8.8An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request...
CVE-2025-61156HIGH7.8Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil...
CVE-2025-10932HIGH8.2Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Trans...
CVE-2025-64140HIGH8.8Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowin...
CVE-2025-64134HIGH7.1Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure it...
CVE-2025-64131HIGH7.5Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtai...
CVE-2025-61161HIGH8.4DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an un...
CVE-2025-40084HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before ...
CVE-2025-64284HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64216HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64195HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-60075HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflecte...
CVE-2025-11702HIGH8.8GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before...
CVE-2025-62776HIGH8.4The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurel...
CVE-2025-62801HIGH7.8FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerabi...
CVE-2025-62727HIGH7.5Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now