2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-28946HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-27361HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Expre...
CVE-2025-25173HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FasterThemes FastB...
CVE-2025-25171HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authen...
CVE-2025-24774HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - C...
CVE-2025-24769HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-24765HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow im...
CVE-2025-24760HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-23973HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugudlabs SpecFit-...
CVE-2025-6761HIGH7.3A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical....
CVE-2025-2940HIGH7.2The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers...
CVE-2025-36529HIGH8.6An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnera...
CVE-2025-6752HIGH8.8A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critica...
CVE-2025-6751HIGH8.8A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the func...
CVE-2025-6736HIGH8.8A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown func...
CVE-2025-6735HIGH8.8A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file ...
CVE-2025-6734HIGH8.8A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the fu...
CVE-2025-6733HIGH8.8A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been declared as critical. This vulnerability aff...
CVE-2025-6732HIGH8.8A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been classified as critical. This affects the fun...
CVE-2025-52904HIGH8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52903HIGH8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52477HIGH8.6Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5...
CVE-2025-34048HIGH8.7A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL...
CVE-2025-34047HIGH8.7A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attack...
CVE-2025-34045HIGH7.5A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now