2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-32144HIGH8.8Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injecti...
CVE-2025-32143HIGH8.8Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue a...
CVE-2025-32107HIGH8OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build ...
CVE-2025-31379HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in programphases Inse...
CVE-2025-31378HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in danbwb Oppso Unit ...
CVE-2025-31041HIGH7.5Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows E...
CVE-2025-31040HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31028HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Huseyin Berberoglu...
CVE-2025-31021HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dolby_uk Mobile Sm...
CVE-2025-31015HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31014HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-2636HIGH8.1The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all v...
CVE-2025-0128HIGH8.7A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of P...
CVE-2025-0127HIGH7.1A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2025-0126HIGH8.3When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to imperson...
CVE-2025-0120HIGH7A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices al...
CVE-2025-32808HIGH7.7W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into t...
CVE-2025-29915HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th...
CVE-2025-23010HIGH7.2An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and...
CVE-2025-23009HIGH7.2A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attac...
CVE-2025-23008HIGH7.2An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low ...
CVE-2025-32383HIGH7.2MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model an...
CVE-2025-29017HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file uplo...
CVE-2025-27813HIGH8.1MSI Center before 2.0.52.0 has Missing PE Signature Validation.
CVE-2025-27812HIGH8.1MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now