2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3617HIGH7.8A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files a...
CVE-2025-33027HIGH7.8In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers...
CVE-2025-33026HIGH7.8In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass...
CVE-2025-32780HIGH7.3BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerab...
CVE-2025-32948HIGH7.5The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send request...
CVE-2025-32947HIGH7.5This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite lo...
CVE-2025-29281HIGH8.8In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component...
CVE-2025-32929HIGH7.5Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-bar...
CVE-2025-31011HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers S...
CVE-2025-30962HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster ...
CVE-2025-26992HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing...
CVE-2025-26959HIGH8.8Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue ...
CVE-2025-26958HIGH7.5Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrain...
CVE-2025-26954HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooE...
CVE-2025-26944HIGH7.5Missing Authorization vulnerability in Crocoblock JetPopup jet-popup allows Accessing Functionality Not Properly Constra...
CVE-2025-26942HIGH7.5Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Const...
CVE-2025-26894HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26889HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26743HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Qu...
CVE-2025-26741HIGH8.8Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Pri...
CVE-2025-3575HIGH8.7Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor...
CVE-2025-3574HIGH8.7Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor...
CVE-2025-29984HIGH7.3Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privilege...
CVE-2025-29983HIGH7.3Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following'...
CVE-2025-31491HIGH8.6AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now