2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-60164HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in NewsMAN NewsmanApp newsmanapp allows Stored XSS.This issue affects Ne...
CVE-2025-60153HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-60150HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-60126HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-60118HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Potenzaglobalsolut...
CVE-2025-60116HIGH8.8Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post al...
CVE-2025-60111HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core javo-core allows Authentication Bypass.This issu...
CVE-2025-60110HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup AllIn...
CVE-2025-60109HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe...
CVE-2025-60108HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe...
CVE-2025-60107HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe...
CVE-2025-59012HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Travele...
CVE-2025-59011HIGH7.5Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-59010HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager a...
CVE-2025-59002HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Buil...
CVE-2025-4957HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileG...
CVE-2025-48107HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode unco...
CVE-2025-1862HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied file...
CVE-2025-11021HIGH7.5A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applicati...
CVE-2025-10871HIGH7.2An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 b...
CVE-2025-10858HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1...
CVE-2025-35027HIGH7.3Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a com...
CVE-2025-10747HIGH7.2The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2025-10997HIGH7.8A flaw has been found in Open Babel up to 3.1.1. Impacted is the function ChemKinFormat::CheckSpecies of the file /src/f...
CVE-2025-10996HIGH7.8A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now