2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15564MEDIUM5.5A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::...
CVE-2025-15477MEDIUM6.5The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr...
CVE-2025-15476MEDIUM4.3The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-15491MEDIUM5.5The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate...
CVE-2025-15267MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion...
CVE-2025-13463MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in a...
CVE-2025-12803MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor...
CVE-2025-12159MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_conte...
CVE-2025-31990MEDIUM6.8Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) att...
CVE-2025-68621HIGH7.4Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person...
CVE-2025-15320LOW3.3Tanium addressed a denial of service vulnerability in Tanium Client.
CVE-2025-69216MEDIUM6.5OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au...
CVE-2025-69214HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ...
CVE-2025-69212HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri...
CVE-2025-70963HIGH7.6Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived ...
CVE-2025-64175HIGH8.8Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not...
CVE-2025-64111CRITICAL9.8Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-...
CVE-2025-13523MEDIUM5.4Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rend...
CVE-2025-13818MEDIUM6.7Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
CVE-2025-10753MEDIUM5.3The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions ...
CVE-2025-15566HIGH8.8A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress ...
CVE-2025-68458LOW3.7Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTT...
CVE-2025-68157LOW3.7Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTT...
CVE-2025-32393MEDIUM6.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2025-12131MEDIUM6.5A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now