2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3540HIGH8.6A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V1...
CVE-2025-3539HIGH8.6A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Ma...
CVE-2025-3445HIGH8.1A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a...
CVE-2025-3538HIGH8.8A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function a...
CVE-2025-3418HIGH8.8The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due...
CVE-2025-29834HIGH7.5Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2025-29803HIGH7.3Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an auth...
CVE-2025-32367HIGH8.6The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure D...
CVE-2025-23389HIGH8.4A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML...
CVE-2025-23388HIGH8.2A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: fro...
CVE-2025-31932HIGH8.8Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrar...
CVE-2025-3434HIGH7.2The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in al...
CVE-2025-32681HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log ...
CVE-2025-32672HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32671HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Sci...
CVE-2025-32663HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32656HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32654HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32650HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Acces...
CVE-2025-32633HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset...
CVE-2025-32632HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Autom...
CVE-2025-32631HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in oxygensuite Oxygen MyDat...
CVE-2025-32629HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CMSJunkie - WordPress Bu...
CVE-2025-32627HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32618HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishli...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now