2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62753HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59131HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue...
CVE-2025-15114CRITICAL9.8Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar...
CVE-2025-15113CRITICAL9.3Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that all...
CVE-2025-15112MEDIUM5.4Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that...
CVE-2025-15111CRITICAL9.8Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized a...
CVE-2025-15360HIGH7.2A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd...
CVE-2025-66723HIGH7.5inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Librar...
CVE-2025-61594HIGH7.5URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Rub...
CVE-2025-15357CRITICAL9.8A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?fla...
CVE-2025-15356HIGH8.8A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file ...
CVE-2025-14987MEDIUM5.3When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task c...
CVE-2025-14986LOW1.3When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates...
CVE-2025-69261HIGH7.5WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instan...
CVE-2025-69257MEDIUM6.7theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi...
CVE-2025-69210MEDIUM5.4FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cr...
CVE-2025-66823MEDIUM5.4An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to...
CVE-2025-50343CRITICAL9.8An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfie...
CVE-2025-15354CRITICAL9.8A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the ...
CVE-2025-15353CRITICAL9.8A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of...
CVE-2025-69256HIGH7.5The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Sta...
CVE-2025-66835HIGH7.1TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary...
CVE-2025-66834HIGH7.3A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadshe...
CVE-2025-66824HIGH8.7A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference fun...
CVE-2025-15264HIGH7.3A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthum...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now