2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46658CRITICAL9.8An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.
CVE-2025-43979HIGH7.4An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute ar...
CVE-2025-54874CRITICAL9.8OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead...
CVE-2025-50707CRITICAL9.8An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
CVE-2025-50706CRITICAL9.8An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
CVE-2025-47152MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396...
CVE-2025-46958MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-44964LOW3.9A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obta...
CVE-2025-2611CRITICAL9.3The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject she...
CVE-2025-29745HIGH7.5A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser...
CVE-2025-27931MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using ...
CVE-2025-7033HIGH7.8A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re...
CVE-2025-7032HIGH7.8A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re...
CVE-2025-7025HIGH7.8A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re...
CVE-2025-54987CRITICAL9.8A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ...
CVE-2025-54948CRITICAL9.8A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ...
CVE-2025-8555MEDIUM5.4A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct...
CVE-2025-8554MEDIUM5.4A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some...
CVE-2025-8553MEDIUM5.4A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code ...
CVE-2025-8552MEDIUM5.4A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the...
CVE-2025-8551MEDIUM5.4A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u...
CVE-2025-8295MEDIUM6.4The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ paramete...
CVE-2025-8294MEDIUM6.4The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all v...
CVE-2025-6207HIGH8.8The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2025-5061HIGH8.8The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now