2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58047HIGH7.5Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0....
CVE-2025-58335HIGH7.5In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54...
CVE-2025-58334HIGH8.8In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-p...
CVE-2025-57767HIGH7.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2...
CVE-2025-8067HIGH8.5A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system....
CVE-2025-9578HIGH7.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2025-54742HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2025-54731HIGH8.1Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showc...
CVE-2025-54724HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo al...
CVE-2025-54716HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54714HIGH7.1Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incor...
CVE-2025-54710HIGH7.1Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Co...
CVE-2025-54029HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce cs...
CVE-2025-53588HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR S...
CVE-2025-53584HIGH8.1Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket S...
CVE-2025-53583HIGH8.1Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object In...
CVE-2025-53579HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captcha.eu Captcha...
CVE-2025-53578HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53576HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53572HIGH8.1Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injectio...
CVE-2025-53334HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53328HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53326HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53289HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Theme Blvd W...
CVE-2025-53248HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now