2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8875HIGH7.8Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-...
CVE-2025-7971HIGH7.3A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the speci...
CVE-2025-40758HIGH8.7A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendi...
CVE-2025-38738HIGH7.8SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment ...
CVE-2025-36613HIGH7.8SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain...
CVE-2025-36612HIGH7.8SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. ...
CVE-2025-9036HIGH8.5A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This to...
CVE-2025-7973HIGH8.5A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations...
CVE-2025-7774HIGH8.8A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials c...
CVE-2025-7773HIGH8.8A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number i...
CVE-2025-8715HIGH8.8Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code...
CVE-2025-8714HIGH8.8Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary ...
CVE-2025-8958HIGH8.8A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functi...
CVE-2025-54697HIGH7.2Incorrect Privilege Assignment vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-d...
CVE-2025-54692HIGH7.5Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing ...
CVE-2025-54690HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54689HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54679HIGH7.5Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free ...
CVE-2025-52823HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ovatheme Cube Port...
CVE-2025-52820HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin Woo...
CVE-2025-52806HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-52801HIGH7.3Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Con...
CVE-2025-52800HIGH7.3Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing F...
CVE-2025-52788HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson C...
CVE-2025-52785HIGH7.1Missing Authorization vulnerability in softnwords SMM API smm-api allows Exploiting Incorrectly Configured Access Contro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now