2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1677HIGH7.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and...
CVE-2025-1073HIGH7.5Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unaut...
CVE-2025-27350HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice V...
CVE-2025-23386HIGH7.8A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera...
CVE-2025-22279HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32687HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review ...
CVE-2025-32668HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32160HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32158HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32145HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2025-32128HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby L...
CVE-2025-32119HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate ...
CVE-2025-32116HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master q...
CVE-2025-32115HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping ...
CVE-2025-32114HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist...
CVE-2025-31524HIGH8.8Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Es...
CVE-2025-30582HIGH8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/C...
CVE-2025-3417HIGH8.8The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati...
CVE-2025-2809HIGH7.3The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all version...
CVE-2025-2805HIGH7.3The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,...
CVE-2025-0539HIGH8.8In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests th...
CVE-2025-3102HIGH8.1The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading ...
CVE-2025-26480HIGH7.5Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. A...
CVE-2025-26330HIGH7Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthen...
CVE-2025-30660HIGH8.7An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper N...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now