2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49251HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49180HIGH7.8A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. T...
CVE-2025-49179HIGH7.3A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer ...
CVE-2025-49176HIGH7.3A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximu...
CVE-2025-48333HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - Wo...
CVE-2025-48274HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job...
CVE-2025-48145HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Tr...
CVE-2025-48118HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Wooc...
CVE-2025-47572HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39508HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Cor...
CVE-2025-39486HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie ...
CVE-2025-32549HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30988HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ El...
CVE-2025-30562HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdistillery Navig...
CVE-2025-29002HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-28991HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-28972HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Suhas Surse WP Emp...
CVE-2025-24761HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-4879HIGH7.8Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2025-0320HIGH7.8Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Win...
CVE-2025-6020HIGH7.8A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, ...
CVE-2025-5777HIGH7.5Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual serv...
CVE-2025-5349HIGH8.8Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
CVE-2025-4365HIGH7.5Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
CVE-2025-6173HIGH7.2A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now