2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11889HIGH7.2The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...
CVE-2025-11504HIGH7.5The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9...
CVE-2025-62868HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-62254HIGH7.5The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 th...
CVE-2025-58429HIGH8.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-62688HIGH7.1An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v...
CVE-2025-62498HIGH8.8A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The ...
CVE-2025-61977HIGH7.3A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve...
CVE-2025-59500HIGH8.8Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network...
CVE-2025-58456HIGH8.2A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab...
CVE-2025-58078HIGH8.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera...
CVE-2025-12100HIGH8.8Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a...
CVE-2025-55067HIGH7.1The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th...
CVE-2025-54964HIGH8.4An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi...
CVE-2025-12044HIGH7.5Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload...
CVE-2025-6980HIGH7.5Captive Portal can expose sensitive information
CVE-2025-6979HIGH8.8Captive Portal can allow authentication bypass
CVE-2025-6978HIGH7.2Diagnostics command injection vulnerability
CVE-2025-54808HIGH7.8Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat...
CVE-2025-23352HIGH7.8NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali...
CVE-2025-23347HIGH7.8NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e...
CVE-2025-11621HIGH8.1Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co...
CVE-2025-62713HIGH7.2Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati...
CVE-2025-62169HIGH8.1OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th...
CVE-2025-59048HIGH8.1OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now