2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49363HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49362HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49361HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49360HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49359HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49041MEDIUM6.5Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces...
CVE-2025-14318MEDIUM4.3Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W...
CVE-2025-14314HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit po...
CVE-2025-13498MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ...
CVE-2025-12976MEDIUM6.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-10019MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al...
CVE-2025-68463MEDIUM4.9Bio.Entrez in Biopython through 186 allows doctype XXE.
CVE-2025-68462LOW3.2Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump f...
CVE-2025-68459HIGH7.2RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injec...
CVE-2025-47387HIGH7.8Memory Corruption when processing IOCTLs for JPEG data without verification.
CVE-2025-47382HIGH7.8Memory corruption while loading an invalid firmware in boot loader.
CVE-2025-47372HIGH8.4Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
CVE-2025-47350HIGH7.8Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
CVE-2025-47325MEDIUM5.5Information disclosure while processing system calls with invalid parameters.
CVE-2025-47323HIGH7.8Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-47322HIGH7.8Memory corruption while handling IOCTL calls to set mode.
CVE-2025-47321HIGH7.8Memory corruption while copying packets received from unix clients.
CVE-2025-47320HIGH7.8Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-47319MEDIUM6.7Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-27063HIGH7.8Memory corruption during video playback when video session open fails with time out error.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now