2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48082HIGH8.8Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Esca...
CVE-2025-39534HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Di...
CVE-2025-32657HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32283HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue af...
CVE-2025-31634HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue a...
CVE-2025-30944HIGH7.5Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality ...
CVE-2025-11965HIGH7.5In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to h...
CVE-2025-61035HIGH7.7The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file...
CVE-2025-11086HIGH8.1The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e...
CVE-2025-41110HIGH8.8Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an ...
CVE-2025-41724HIGH7.5An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process wi...
CVE-2025-41722HIGH7.5The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attac...
CVE-2025-41719HIGH8.8A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsuppor...
CVE-2025-62775HIGH8Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
CVE-2025-62771HIGH7.5Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.
CVE-2025-61756HIGH7.5Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-62641HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62590HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62589HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62588HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62587HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62290HIGH7.2Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The suppor...
CVE-2025-61763HIGH8.1Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0....
CVE-2025-61760HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-61752HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now