2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71426 | HIGH | 7.1 | — | Sep 27, 2026 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not... |
| CVE-2025-71425 | HIGH | 7.3 | — | Sep 27, 2026 | Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contr... |
| CVE-2025-71424 | LOW | 3.5 | 0.2% | Sep 27, 2026 | Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and includi... |
| CVE-2025-71423 | HIGH | 7.3 | — | Sep 27, 2026 | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initialize... |
| CVE-2025-71422 | MEDIUM | 5.7 | — | Sep 27, 2026 | Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume fe... |
| CVE-2025-1218 | LOW | 3.4 | 0.2% | Sep 25, 2026 | The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough b... |
| CVE-2025-14181 | MEDIUM | 6.5 | — | Sep 25, 2026 | The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is und... |
| CVE-2025-51457 | HIGH | 8.8 | — | Sep 25, 2026 | D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at ... |
| CVE-2025-14814 | MEDIUM | 6.4 | — | Sep 25, 2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbo... |
| CVE-2025-32000 | MEDIUM | 4.3 | — | Sep 24, 2026 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input... |
| CVE-2025-63564 | CRITICAL | 9.8 | 0.5% | Sep 23, 2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code... |
| CVE-2025-15696 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rende... |
| CVE-2025-36084 | MEDIUM | 5.9 | 0.2% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-12767 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted reg... |
| CVE-2025-1281 | HIGH | 8.8 | 0.6% | Sep 22, 2026 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-1280 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive... |
| CVE-2025-14487 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorizatio... |
| CVE-2025-14486 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in... |
| CVE-2025-14484 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization chec... |
| CVE-2025-71421 | HIGH | 7.2 | 0.4% | Sep 21, 2026 | UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint tha... |
| CVE-2025-71420 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allow... |
| CVE-2025-71419 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration... |
| CVE-2025-12999 | CRITICAL | 9.1 | 0.4% | Sep 21, 2026 | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwa... |
| CVE-2025-15698 | LOW | 3.5 | 0.1% | Sep 19, 2026 | The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could ... |
| CVE-2025-66455 | CRITICAL | 9.8 | 0.7% | Sep 18, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now