2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-43994HIGH7.5Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Fun...
CVE-2025-11145HIGH7.5Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Informa...
CVE-2025-46183HIGH8.2The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker ...
CVE-2025-40024HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost...
CVE-2025-40018HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns clean...
CVE-2025-10861HIGH7.5The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr...
CVE-2025-36361HIGH8.8IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user ...
CVE-2025-10680HIGH8.8OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell comma...
CVE-2025-12028HIGH8.8The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5...
CVE-2025-11889HIGH7.2The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...
CVE-2025-11504HIGH7.5The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9...
CVE-2025-62868HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-62254HIGH7.5The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 th...
CVE-2025-58429HIGH8.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-62688HIGH7.1An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v...
CVE-2025-62498HIGH8.8A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The ...
CVE-2025-61977HIGH7.3A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve...
CVE-2025-59500HIGH8.8Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network...
CVE-2025-58456HIGH8.2A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab...
CVE-2025-58078HIGH8.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera...
CVE-2025-12100HIGH8.8Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a...
CVE-2025-55067HIGH7.1The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th...
CVE-2025-54964HIGH8.4An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi...
CVE-2025-12044HIGH7.5Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload...
CVE-2025-6980HIGH7.5Captive Portal can expose sensitive information

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now