2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49249HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ApusTheme Drone dr...
CVE-2025-49066HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Accor...
CVE-2025-49050HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le...
CVE-2025-49049HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video G...
CVE-2025-49046HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup xProm...
CVE-2025-49045HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super I...
CVE-2025-49043HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Magic...
CVE-2025-48094HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Magic...
CVE-2025-47666HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Image...
CVE-2025-47474HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32123HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5...
CVE-2025-27005HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5...
CVE-2025-69822HIGH7.4An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive informati...
CVE-2025-69821HIGH7.4An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service ...
CVE-2025-36588HIGH8.8Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an S...
CVE-2025-65098HIGH7.4Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s...
CVE-2025-13928HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 1...
CVE-2025-13927HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 1...
CVE-2025-14295HIGH7Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. ...
CVE-2025-10856HIGH8.1Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows Fi...
CVE-2025-10855HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows E...
CVE-2025-67684HIGH7.2Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart ...
CVE-2025-10024HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Educatio...
CVE-2025-4764HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Info...
CVE-2025-27380HIGH7.6HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now