2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66598HIGH7.5A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL...
CVE-2025-66597HIGH7.5A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cr...
CVE-2025-66608HIGH7.5A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl...
CVE-2025-66600HIGH8.8A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP...
CVE-2025-15100HIGH8.8The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including...
CVE-2025-68621HIGH7.4Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person...
CVE-2025-69214HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ...
CVE-2025-69212HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri...
CVE-2025-70963HIGH7.6Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived ...
CVE-2025-64175HIGH8.8Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not...
CVE-2025-15566HIGH8.8A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress ...
CVE-2025-15330HIGH8.8Tanium addressed an improper input validation vulnerability in Deploy.
CVE-2025-15312HIGH7.2Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
CVE-2025-15311HIGH7.8Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
CVE-2025-70073HIGH7.2An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation ...
CVE-2025-15557HIGH8.8An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on ...
CVE-2025-69906HIGH8.8Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o...
CVE-2025-68722HIGH8.8Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i...
CVE-2025-68721HIGH8.1Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat...
CVE-2025-13379HIGH8.6IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2025-15080HIGH8.8Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P...
CVE-2025-61732HIGH8.6A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2025-10314HIGH8.8Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 ...
CVE-2025-11730HIGH7.2A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s...
CVE-2025-13192HIGH8.2The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now