2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60218 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. |
| CVE-2025-60205 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. |
| CVE-2025-59872 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t... |
| CVE-2025-13036 | CRITICAL | 9.2 | 0.3% | Jun 16, 2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending request... |
| CVE-2025-6254 | CRITICAL | 9.8 | 0.5% | Jun 10, 2026 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8... |
| CVE-2025-66276 | CRITICAL | 9.8 | 0.3% | Jun 10, 2026 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250... |
| CVE-2025-10263 | CRITICAL | 9.1 | 0.6% | Jun 9, 2026 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4... |
| CVE-2025-71318 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated ... |
| CVE-2025-71317 | CRITICAL | 9.8 | 0.4% | Jun 5, 2026 | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce... |
| CVE-2025-71316 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS... |
| CVE-2025-67447 | CRITICAL | 9.8 | 1.0% | Jun 4, 2026 | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje... |
| CVE-2025-67446 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u... |
| CVE-2025-14771 | CRITICAL | 9.9 | 0.3% | Jun 3, 2026 | Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0... |
| CVE-2025-53209 | CRITICAL | 9.8 | 0.3% | Jun 2, 2026 | Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff... |
| CVE-2025-41277 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41276 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41275 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41274 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41273 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI... |
| CVE-2025-41272 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41270 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41269 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41268 | CRITICAL | 9.1 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and... |
| CVE-2025-13392 | CRITICAL | 9.8 | 0.5% | May 27, 2026 | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7... |
| CVE-2025-12686 | CRITICAL | 9.8 | 2.8% | May 27, 2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now