2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60223HIGH7.7Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
CVE-2025-60218CRITICAL9.9Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
CVE-2025-60205CRITICAL9.8Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
CVE-2025-60085HIGH8.1Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
CVE-2025-59872CRITICAL9.8HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t...
CVE-2025-59563HIGH8.8Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
CVE-2025-59560HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.
CVE-2025-58954HIGH8.1Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
CVE-2025-58953HIGH8.1Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
CVE-2025-58952HIGH8.1Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
CVE-2025-58924HIGH8.1Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
CVE-2025-49403HIGH7.5Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.
CVE-2025-48643HIGH7.8In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local...
CVE-2025-48640HIGH8In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T...
CVE-2025-48617HIGH7.8In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. ...
CVE-2025-48571MEDIUM4.3In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er...
CVE-2025-31013HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow...
CVE-2025-15642MEDIUM6.8Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad...
CVE-2025-15641MEDIUM6.8Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad...
CVE-2025-71261HIGH8.6An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8....
CVE-2025-14272HIGH8.3A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerabili...
CVE-2025-13036CRITICAL9.2An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending request...
CVE-2025-11694HIGH8.7A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and sourc...
CVE-2025-68045HIGH7.5Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
CVE-2025-9912MEDIUM6.3Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now