2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6426HIGH8.8The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affec...
CVE-2025-6425MEDIUM4.3An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified ...
CVE-2025-6424CRITICAL9.8A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140...
CVE-2025-39205HIGH7.1A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol a...
CVE-2025-39204HIGH8.5A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface...
CVE-2025-39203HIGH7.1A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from ...
CVE-2025-39202HIGH8.1A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with lo...
CVE-2025-39201MEDIUM6.1A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to...
CVE-2025-2403HIGH8.7A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in ...
CVE-2025-1718HIGH7.1An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device...
CVE-2025-6206HIGH7.5The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2025-3092HIGH7.5An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
CVE-2025-3091HIGH7.5An low privileged remote attacker in possession of the second factor for another user can login as that user without kno...
CVE-2025-5258MEDIUM6.4The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter...
CVE-2025-50213CRITICAL9.8Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow ...
CVE-2025-3090HIGH8.2An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authent...
CVE-2025-2962HIGH7.5A denial-of-service issue in the dns implemenation could cause an infinite loop.
CVE-2025-48890CRITICAL9.8WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje...
CVE-2025-43879CRITICAL9.8WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje...
CVE-2025-43877MEDIUM5.4WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be...
CVE-2025-41427HIGH8.8WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command...
CVE-2025-36519MEDIUM5.3Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B...
CVE-2025-52570LOW1.7Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. I...
CVE-2025-52568HIGH8.8NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issue...
CVE-2025-52566HIGH8.8llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now