2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47695HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47694HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Design...
CVE-2025-47579HIGH8.1Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue...
CVE-2025-47571HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47570HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooComm...
CVE-2025-32689HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects ...
CVE-2025-9872HIGH8.8Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe...
CVE-2025-9712HIGH8.8Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe...
CVE-2025-55148HIGH7.6Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z...
CVE-2025-55147HIGH8.8CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before...
CVE-2025-55145HIGH8.9Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z...
CVE-2025-55142HIGH8.8Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z...
CVE-2025-55141HIGH8.8Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z...
CVE-2025-52915HIGH7.2K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCT...
CVE-2025-52322HIGH7.5An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session...
CVE-2025-9951HIGH7.2A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execu...
CVE-2025-9364HIGH8.8An open database issue exists in the affected product and version. The security issue stems from an over permissive Redi...
CVE-2025-9166HIGH7.5A denial-of-service security issue exists in the affected product and version. The security issue stems from the control...
CVE-2025-9161HIGH8.8A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the ...
CVE-2025-9160HIGH7A code execution security issue exists in the affected product. An attacker with physical access could abuse the mainten...
CVE-2025-9065HIGH8.8A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of ...
CVE-2025-7970HIGH7.5A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within th...
CVE-2025-7350HIGH8.6A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can ...
CVE-2025-48208HIGH8.8Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat ....
CVE-2025-24404HIGH8.8XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now