2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70073HIGH7.2An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation ...
CVE-2025-68121CRITICAL10During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th...
CVE-2025-58190MEDIUM5.3The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can ...
CVE-2025-47911MEDIUM5.3The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which ...
CVE-2025-15557HIGH8.8An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on ...
CVE-2025-15551MEDIUM5.6The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get...
CVE-2025-70792MEDIUM6.1Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu...
CVE-2025-70791MEDIUM6.1Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu...
CVE-2025-69906HIGH8.8Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o...
CVE-2025-69619MEDIUM5.5A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i...
CVE-2025-68723CRITICAL9Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in...
CVE-2025-68643MEDIUM5.4Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre...
CVE-2025-68722HIGH8.8Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i...
CVE-2025-68721HIGH8.1Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat...
CVE-2025-14150MEDIUM6.5IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM...
CVE-2025-13491MEDIUM5.1IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th...
CVE-2025-13379HIGH8.6IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2025-14079MEDIUM5.3The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a...
CVE-2025-13416MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi...
CVE-2025-10258MEDIUM6.3Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r...
CVE-2025-15080HIGH8.8Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P...
CVE-2025-61732HIGH8.6A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2025-10314HIGH8.8Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 ...
CVE-2025-11730HIGH7.2A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s...
CVE-2025-13192HIGH8.2The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now