2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62509HIGH8.1FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version...
CVE-2025-47902HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Pro...
CVE-2025-47901HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti...
CVE-2025-47900HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti...
CVE-2025-3465HIGH8.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB C...
CVE-2025-62429HIGH7.2ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi...
CVE-2025-40012HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/smc: fix warning in smc_rx_splice() when callin...
CVE-2025-40006HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted ...
CVE-2025-26782HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-26781HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-61417HIGH8.8Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att...
CVE-2025-57738HIGH7.2Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus...
CVE-2025-41390HIGH7.8An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s...
CVE-2025-11678HIGH7.5Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS fla...
CVE-2025-56224HIGH8.1A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to by...
CVE-2025-56223HIGH7.5A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Den...
CVE-2025-56219HIGH7.1Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin...
CVE-2025-62577HIGH8.8ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged ...
CVE-2025-11944HIGH7.2A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control...
CVE-2025-11941HIGH8.1A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php...
CVE-2025-11940HIGH7.3A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of ...
CVE-2025-11939HIGH7.2A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu...
CVE-2025-11938HIGH8.1A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se...
CVE-2025-47410HIGH8.8Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all...
CVE-2025-9890HIGH8.8The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now