2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27523HIGH8.7XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Des...
CVE-2025-3053HIGH8.8The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod...
CVE-2025-4579HIGH7.2The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and...
CVE-2025-47885HIGH8.8Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Hea...
CVE-2025-44879HIGH7.5WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerabi...
CVE-2025-26783HIGH7.5An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330,...
CVE-2025-4640HIGH8.3Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default...
CVE-2025-33104HIGH7.6IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2025-2900HIGH7.5IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 th...
CVE-2025-0131HIGH7.1An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto N...
CVE-2025-4639HIGH8.8CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Pe...
CVE-2025-4637HIGH8.7Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file...
CVE-2025-30664HIGH8.2Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege v...
CVE-2025-30663HIGH7Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escal...
CVE-2025-0130HIGH7.5A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenti...
CVE-2025-47710HIGH7.4Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ...
CVE-2025-47708HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forg...
CVE-2025-47707HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ...
CVE-2025-47701HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This is...
CVE-2025-40595HIGH7.2A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By...
CVE-2025-3909HIGH8.1Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the fil...
CVE-2025-3875HIGH7.5Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address t...
CVE-2025-26785HIGH7.5An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-47782HIGH8.9motionEye is an online interface for the software motion, a video surveillance program with motion detection. In version...
CVE-2025-47775HIGH8.6Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now