2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54379CRITICAL9.8LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev...
CVE-2025-54369CRITICAL9.3Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML lo...
CVE-2025-53940HIGH8.5Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central serv...
CVE-2025-3614MEDIUM5.4The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-32429CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4...
CVE-2025-22165HIGH7.3This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac....
CVE-2025-8123HIGH8.8A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown fu...
CVE-2025-7404CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,...
CVE-2025-6260CRITICAL9.8The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta...
CVE-2025-31955MEDIUM6.5HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensi...
CVE-2025-31953MEDIUM6.5HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted ...
CVE-2025-31952HIGH7.1HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless...
CVE-2025-6998HIGH8.7ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remo...
CVE-2025-8115MEDIUM5.4A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by...
CVE-2025-5039HIGH7.8A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to exec...
CVE-2025-45702MEDIUM6.5SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.
CVE-2025-53084MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and...
CVE-2025-50128MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVide...
CVE-2025-48732CRITICAL9.8An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c...
CVE-2025-47061MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46996MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46993MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46410MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality o...
CVE-2025-41420CRITICAL9.6A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4...
CVE-2025-36548CRITICAL9.6A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of W...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now