2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-69908HIGH7.5An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged...
CVE-2025-66720HIGH7.5Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePolicie...
CVE-2025-71157HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_su...
CVE-2025-71156HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registrati...
CVE-2025-71155HIGH7.8In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A ...
CVE-2025-71152HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: dsa: properly keep track of conduit reference ...
CVE-2025-69907HIGH7.5An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and acce...
CVE-2025-71145HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: phy: isp1301: fix non-OF device reference imba...
CVE-2025-14866HIGH8.8The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2025-67847HIGH8.8A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbi...
CVE-2025-3839HIGH8A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user in...
CVE-2025-15351HIGH7.8Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-15350HIGH7.8Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-15349HIGH7.5Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent at...
CVE-2025-15348HIGH7.8Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi...
CVE-2025-15062HIGH7.8Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-15059HIGH7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-11002HIGH7.87-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-53968HIGH7.5This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An...
CVE-2025-14751HIGH8.7A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m...
CVE-2025-14750HIGH8.7The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally con...
CVE-2025-66428HIGH8.8An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
CVE-2025-69321HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand S...
CVE-2025-69320HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand M...
CVE-2025-69319HIGH7.5Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now