2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48882HIGH8.7PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to versio...
CVE-2025-2503HIGH7.1An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to per...
CVE-2025-2502HIGH8.5An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to ele...
CVE-2025-2501HIGH8.5An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate pr...
CVE-2025-4992HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Re...
CVE-2025-4991HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3...
CVE-2025-4990HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIEN...
CVE-2025-4989HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2...
CVE-2025-4988HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer...
CVE-2025-4986HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENC...
CVE-2025-4985HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3D...
CVE-2025-4984HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPER...
CVE-2025-4983HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DE...
CVE-2025-0602HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DE...
CVE-2025-48331HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter wooc...
CVE-2025-4433HIGH8.8Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrativ...
CVE-2025-5190HIGH8.8The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is...
CVE-2025-1763HIGH8.7An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass...
CVE-2025-4636HIGH7.8Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains co...
CVE-2025-48936HIGH8.8Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vuln...
CVE-2025-48492HIGH8.8GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with acc...
CVE-2025-47697HIGH7.5Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated a...
CVE-2025-41385HIGH7.2An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS comman...
CVE-2025-48889HIGH7.5Gradio is an open-source Python package that allows quick building of demos and web application for machine learning mod...
CVE-2025-48881HIGH8.3Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now