2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15028HIGH7.2The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ...
CVE-2025-15039CRITICAL9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require...
CVE-2025-14779LOW3.8The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet...
CVE-2025-13909MEDIUM4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT...
CVE-2025-13736LOW3.7When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo...
CVE-2025-13394MEDIUM5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque...
CVE-2025-12627LOW2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated...
CVE-2025-11850MEDIUM4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us...
CVE-2025-15678MEDIUM6.1The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use...
CVE-2025-63823CRITICAL9.8My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote ...
CVE-2025-63822HIGH8.1SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate...
CVE-2025-70962HIGH7.5Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ...
CVE-2025-15677LOW3.5The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin...
CVE-2025-29296CRITICAL9.8H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V...
CVE-2025-15631MEDIUM5.9A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al...
CVE-2025-15630MEDIUM5.9A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t...
CVE-2025-15629HIGH7.5A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati...
CVE-2025-15628HIGH7.5Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr...
CVE-2025-15627HIGH7.5A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to...
CVE-2025-15544MEDIUM5.9A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assoc...
CVE-2025-9291MEDIUM6.5A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif...
CVE-2025-15673MEDIUM4.9The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an...
CVE-2025-15672HIGH8.1The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa...
CVE-2025-71401MEDIUM5.9better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B...
CVE-2025-71400HIGH7.1better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now