2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10231HIGH7.8An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstanc...
CVE-2025-7718HIGH8.8The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation ...
CVE-2025-10227MEDIUM4.6Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2...
CVE-2025-10226CRITICAL9.8Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0....
CVE-2025-10225HIGH8.7Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in...
CVE-2025-10224HIGH7.1Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on...
CVE-2025-10223HIGH8.1Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windo...
CVE-2025-10222MEDIUM4.8Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon...
CVE-2025-10221MEDIUM6.7Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet ...
CVE-2025-10220CRITICAL9.8Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0....
CVE-2025-10219Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-40979HIGH7DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this...
CVE-2025-40725MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute J...
CVE-2025-10215HIGH7.8DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc...
CVE-2025-10214HIGH7.8DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc...
CVE-2025-10213HIGH7.8DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc...
CVE-2025-36759HIGH8.7Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive informa...
CVE-2025-36758MEDIUM6.3It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Pas...
CVE-2025-36757MEDIUM6.3It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to byp...
CVE-2025-36756MEDIUM5.8A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t...
CVE-2025-9979MEDIUM4.3The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin...
CVE-2025-9943CRITICAL9.1An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t...
CVE-2025-9888MEDIUM4.3The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2025-9857MEDIUM6.4The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-9622MEDIUM4.3The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now