2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31099HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestweblayout Slid...
CVE-2025-27932HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process...
CVE-2025-27718HIGH8.8Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process o...
CVE-2025-2485HIGH8.8The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in ...
CVE-2025-2328HIGH8.8The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion ...
CVE-2025-24386HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-24385HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-24381HIGH8.8Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A...
CVE-2025-24380HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-24379HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-24378HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-24377HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-23383HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-24382HIGH7.3Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-1860HIGH7.7Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptogr...
CVE-2025-30232HIGH7.8A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
CVE-2025-26956HIGH7.6Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2....
CVE-2025-26890HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26874HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in memberspace Member...
CVE-2025-26733HIGH8.2Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2....
CVE-2025-30093HIGH8.1HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authentic...
CVE-2025-2855HIGH7.2A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue...
CVE-2025-29072HIGH7.5An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-l...
CVE-2025-28135HIGH7.5TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.
CVE-2025-22783HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO P...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now