2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49070HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47627HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39487HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie ...
CVE-2025-32311HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Press...
CVE-2025-32297HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl...
CVE-2025-31037HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey h...
CVE-2025-28980HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Wea...
CVE-2025-28978HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB B...
CVE-2025-28968HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac ...
CVE-2025-24780HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcar...
CVE-2025-24771HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content ...
CVE-2025-7060HIGH8.1A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part ...
CVE-2025-38176HIGH7.8In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode(...
CVE-2025-38175HIGH7.8In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Comm...
CVE-2025-5920HIGH7.5The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secr...
CVE-2025-30979HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelatin...
CVE-2025-30969HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Im...
CVE-2025-30947HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade...
CVE-2025-28969HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widg...
CVE-2025-28967HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Conta...
CVE-2025-24735HIGH7.7Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live...
CVE-2025-53600HIGH7.5Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
CVE-2025-32918HIGH8.8Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions...
CVE-2025-5372HIGH8.8A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function r...
CVE-2025-6814HIGH7.5The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now