2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68563HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68540HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68537HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68530HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68519HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands fo...
CVE-2025-68506HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68496HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User F...
CVE-2025-68038HIGH7.2Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object I...
CVE-2025-67909HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-wo...
CVE-2025-67622HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Store...
CVE-2025-68730HIGH7.8In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix page fault in ivpu_bo_unbind_all_bo...
CVE-2025-68724HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymm...
CVE-2025-68379HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix null deref on srq->rq.queue after res...
CVE-2025-68370HIGH7.8In the Linux kernel, the following vulnerability has been resolved: coresight: tmc: add the handle of the event to the ...
CVE-2025-68369HIGH7.5In the Linux kernel, the following vulnerability has been resolved: ntfs3: init run lock for extend inode After settin...
CVE-2025-68360HIGH8.2In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: wed: use proper wed reference in mt76 w...
CVE-2025-68352HIGH7.8In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix out-of-bounds memory access in ch34...
CVE-2025-68349HIGH7.5In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark...
CVE-2025-68347HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: fix buffer overflow in hwdep r...
CVE-2025-66445HIGH7.1Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hit...
CVE-2025-66444HIGH8.2Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hit...
CVE-2025-15053HIGH7.3A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the...
CVE-2025-15050HIGH8.8A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown ...
CVE-2025-68696HIGH8.2httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of lea...
CVE-2025-68664HIGH8.2LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a seriali...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now