2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49848HIGH8.4An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper v...
CVE-2025-49158HIGH7.8An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to esc...
CVE-2025-49157HIGH7.8A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalat...
CVE-2025-49156HIGH7.8A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privil...
CVE-2025-49155HIGH8.8An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacke...
CVE-2025-49154HIGH7.8An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allo...
CVE-2025-34511HIGH8.8Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through vers...
CVE-2025-34510HIGH8.8Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10...
CVE-2025-34509HIGH7.5Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 1...
CVE-2025-47866HIGH7.5An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att...
CVE-2025-33122HIGH7.5IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in I...
CVE-2025-49879HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho litho all...
CVE-2025-49854HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anh Tran Slim SEO ...
CVE-2025-49508HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49451HIGH7.5Path Traversal: '.../...//' vulnerability in yannisraft Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid w...
CVE-2025-49415HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fastw3b LLC FW Gallery f...
CVE-2025-49331HIGH7.2Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows ...
CVE-2025-49316HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: ...
CVE-2025-49312HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution Ech...
CVE-2025-49266HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimat...
CVE-2025-49261HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49260HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49259HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49258HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49257HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now