2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1487HIGH7.1The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, ...
CVE-2025-1486HIGH7.1The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, ...
CVE-2025-1436HIGH7.1The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisat...
CVE-2025-1401HIGH7.1The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in t...
CVE-2025-1257HIGH7.5An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and ...
CVE-2025-2107HIGH7.5The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResul...
CVE-2025-2106HIGH7.5The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of th...
CVE-2025-25293HIGH7.5ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and...
CVE-2025-25975HIGH7.5An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function
CVE-2025-0118HIGH8A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls ...
CVE-2025-0117HIGH7.1A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a ...
CVE-2025-0114HIGH7.5A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an un...
CVE-2025-26260HIGH8.8Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can defin...
CVE-2025-25711HIGH8.8An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to ...
CVE-2025-20209HIGH7.5A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthen...
CVE-2025-20146HIGH8.6A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services...
CVE-2025-20142HIGH8.6A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS X...
CVE-2025-20141HIGH7.4A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS X...
CVE-2025-20138HIGH8.8A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary co...
CVE-2025-20115HIGH8.6A vulnerability in confederation implementation for the Border Gateway Protocol (BGP)&nbsp;in Cisco IOS XR Software coul...
CVE-2025-1683HIGH7.8Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an ...
CVE-2025-0884HIGH7.3Unquoted Search Path or Element vulnerability in OpenText™ Service Manager.  The vulnerability could allow a user to ga...
CVE-2025-0813HIGH7CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized use...
CVE-2025-2240HIGH7.5A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnera...
CVE-2025-27788HIGH7.5JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted docu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now