2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71426HIGH7.1Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not...
CVE-2025-71425HIGH7.3Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contr...
CVE-2025-71424LOW3.5Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and includi...
CVE-2025-71423HIGH7.3Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initialize...
CVE-2025-71422MEDIUM5.7Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume fe...
CVE-2025-1218LOW3.4The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough b...
CVE-2025-14181MEDIUM6.5The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is und...
CVE-2025-51457HIGH8.8D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at ...
CVE-2025-14814MEDIUM6.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbo...
CVE-2025-32000MEDIUM4.3HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input...
CVE-2025-63564CRITICAL9.8SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code...
CVE-2025-15696MEDIUM6.8The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rende...
CVE-2025-36084MEDIUM5.9IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-12767MEDIUM5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted reg...
CVE-2025-1281HIGH8.8The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-1280MEDIUM6.5The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive...
CVE-2025-14487MEDIUM5.3The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorizatio...
CVE-2025-14486MEDIUM5.3The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in...
CVE-2025-14484MEDIUM5.3The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization chec...
CVE-2025-71421HIGH7.2UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint tha...
CVE-2025-71420MEDIUM4.3UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allow...
CVE-2025-71419MEDIUM5.4UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration...
CVE-2025-12999CRITICAL9.1UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwa...
CVE-2025-15698LOW3.5The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could ...
CVE-2025-66455CRITICAL9.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now