2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15026CRITICAL9.8Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import modul...
CVE-2025-68280MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files ...
CVE-2025-12513MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-12511MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-69087HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68865CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility ...
CVE-2025-68850HIGH7.5Missing Authorization vulnerability in codepeople Sell Downloads sell-downloads allows Exploiting Incorrectly Configured...
CVE-2025-68547HIGH7.5Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Confi...
CVE-2025-68044HIGH8.6Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restauran...
CVE-2025-68033HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allo...
CVE-2025-68029MEDIUM6.3Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system...
CVE-2025-68014MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embed...
CVE-2025-31048CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server...
CVE-2025-31047HIGH8.8Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Them...
CVE-2025-31046MEDIUM4.3Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Co...
CVE-2025-31044HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE...
CVE-2025-30633CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Nat...
CVE-2025-13056MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-12519MEDIUM5.3Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows...
CVE-2025-68766In the Linux kernel, the following vulnerability has been resolved: irqchip/mchp-eic: Fix error code in mchp_eic_domain...
CVE-2025-68765In the Linux kernel, the following vulnerability has been resolved: mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_st...
CVE-2025-68764HIGH7.8In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noex...
CVE-2025-68763In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Correctly handle return of sg_ne...
CVE-2025-68762In the Linux kernel, the following vulnerability has been resolved: net: netpoll: initialize work queue before error ch...
CVE-2025-68761HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hfs: fix potential use after free in hfs_correct_ne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now