2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40084HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before ...
CVE-2025-64284HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64216HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64195HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-60075HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflecte...
CVE-2025-11702HIGH8.8GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before...
CVE-2025-62776HIGH8.4The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurel...
CVE-2025-62801HIGH7.8FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerabi...
CVE-2025-62727HIGH7.5Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthent...
CVE-2025-59837HIGH7.2Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy doma...
CVE-2025-40843HIGH7.8CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2025-12425HIGH7.8Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12423HIGH7.5Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19....
CVE-2025-60805HIGH7.5An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive...
CVE-2025-60800HIGH7.5Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce...
CVE-2025-60354HIGH7.5Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.
CVE-2025-54605HIGH7.5Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).
CVE-2025-54604HIGH7.5Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).
CVE-2025-60858HIGH7.5Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration...
CVE-2025-60349HIGH7.5An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E...
CVE-2025-56399HIGH8.8alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) ...
CVE-2025-61107HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p...
CVE-2025-61106HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p...
CVE-2025-61104HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tl...
CVE-2025-61103HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_l...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now