2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-25382HIGH7.5An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitraril...
CVE-2025-26933HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-25614HIGH8.8Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the pers...
CVE-2025-2153HIGH8.1A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the...
CVE-2025-2151HIGH8.8A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects t...
CVE-2025-2148HIGH7.5A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is th...
CVE-2025-2147HIGH7.5A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management Sys...
CVE-2025-27256HIGH8.3Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentic...
CVE-2025-27255HIGH8Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user...
CVE-2025-27254HIGH8CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's s...
CVE-2025-2132HIGH7.2A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/i...
CVE-2025-2126HIGH8.8A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects som...
CVE-2025-2121HIGH8.8A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an u...
CVE-2025-2118HIGH7.3A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown ...
CVE-2025-27822HIGH7.5An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily swit...
CVE-2025-2024HIGH7.8Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-27607HIGH8.8Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger ...
CVE-2025-27604HIGH7.5XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the ...
CVE-2025-0162HIGH7.1IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processin...
CVE-2025-27597HIGH8.9Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnera...
CVE-2025-1887HIGH7.1SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an...
CVE-2025-1886HIGH7.1Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated a...
CVE-2025-26331HIGH7.8Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injectio...
CVE-2025-1309HIGH8.8The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-27795HIGH7.5ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now