2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58954HIGH8.1Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
CVE-2025-58953HIGH8.1Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
CVE-2025-58952HIGH8.1Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
CVE-2025-58924HIGH8.1Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
CVE-2025-49403HIGH7.5Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.
CVE-2025-48643HIGH7.8In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local...
CVE-2025-48640HIGH8In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T...
CVE-2025-48617HIGH7.8In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. ...
CVE-2025-48571MEDIUM4.3In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er...
CVE-2025-31013HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow...
CVE-2025-15642MEDIUM6.8Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad...
CVE-2025-15641MEDIUM6.8Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad...
CVE-2025-71261HIGH8.6An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8....
CVE-2025-14272HIGH8.3A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerabili...
CVE-2025-13036CRITICAL9.2An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending request...
CVE-2025-11694HIGH8.7A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and sourc...
CVE-2025-68045HIGH7.5Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
CVE-2025-9912MEDIUM6.3Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit...
CVE-2025-10262MEDIUM6.3Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu...
CVE-2025-69332MEDIUM6.5Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
CVE-2025-68872HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.
CVE-2025-68851HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
CVE-2025-68840HIGH7.1Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
CVE-2025-68049MEDIUM6.3Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
CVE-2025-60175MEDIUM4.4Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now