2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15028 | HIGH | 7.2 | 0.2% | Aug 6, 2026 | The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ... |
| CVE-2025-15039 | CRITICAL | 9.4 | — | Aug 6, 2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require... |
| CVE-2025-14779 | LOW | 3.8 | 0.2% | Aug 6, 2026 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet... |
| CVE-2025-13909 | MEDIUM | 4.3 | — | Aug 6, 2026 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT... |
| CVE-2025-13736 | LOW | 3.7 | — | Aug 6, 2026 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo... |
| CVE-2025-13394 | MEDIUM | 5.4 | — | Aug 6, 2026 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque... |
| CVE-2025-12627 | LOW | 2.4 | — | Aug 6, 2026 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated... |
| CVE-2025-11850 | MEDIUM | 4.3 | — | Aug 6, 2026 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us... |
| CVE-2025-15678 | MEDIUM | 6.1 | — | Aug 6, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use... |
| CVE-2025-63823 | CRITICAL | 9.8 | 0.4% | Aug 5, 2026 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote ... |
| CVE-2025-63822 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate... |
| CVE-2025-70962 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ... |
| CVE-2025-15677 | LOW | 3.5 | — | Aug 5, 2026 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin... |
| CVE-2025-29296 | CRITICAL | 9.8 | 2.2% | Aug 4, 2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V... |
| CVE-2025-15631 | MEDIUM | 5.9 | — | Aug 3, 2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al... |
| CVE-2025-15630 | MEDIUM | 5.9 | — | Aug 3, 2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t... |
| CVE-2025-15629 | HIGH | 7.5 | — | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati... |
| CVE-2025-15628 | HIGH | 7.5 | — | Aug 3, 2026 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr... |
| CVE-2025-15627 | HIGH | 7.5 | — | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to... |
| CVE-2025-15544 | MEDIUM | 5.9 | — | Aug 3, 2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc... |
| CVE-2025-9291 | MEDIUM | 6.5 | — | Aug 3, 2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif... |
| CVE-2025-15673 | MEDIUM | 4.9 | — | Aug 3, 2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an... |
| CVE-2025-15672 | HIGH | 8.1 | — | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa... |
| CVE-2025-71401 | MEDIUM | 5.9 | — | Aug 2, 2026 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B... |
| CVE-2025-71400 | HIGH | 7.1 | — | Aug 2, 2026 | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now