2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27852 | MEDIUM | 5 | 0.1% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack... |
| CVE-2025-32425 | MEDIUM | 5.5 | 0.2% | May 13, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-29338 | MEDIUM | 5.6 | 0.2% | May 13, 2026 | NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff... |
| CVE-2025-14767 | MEDIUM | 5.5 | 0.2% | May 13, 2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text... |
| CVE-2025-14033 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi... |
| CVE-2025-9989 | MEDIUM | 4.4 | 0.2% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2025-9988 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat... |
| CVE-2025-9987 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2025-14755 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct... |
| CVE-2025-61971 | MEDIUM | 5.9 | 0.1% | May 13, 2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf... |
| CVE-2025-15463 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers... |
| CVE-2025-67604 | MEDIUM | 5.3 | 0.4% | May 12, 2026 | A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0... |
| CVE-2025-53870 | MEDIUM | 6.7 | 0.6% | May 12, 2026 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2025-53680 | MEDIUM | 6.7 | 0.6% | May 12, 2026 | An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul... |
| CVE-2025-36515 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may... |
| CVE-2025-36510 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver... |
| CVE-2025-35991 | MEDIUM | 5.6 | 0.1% | May 12, 2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat... |
| CVE-2025-35979 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio... |
| CVE-2025-35969 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3... |
| CVE-2025-27723 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke... |
| CVE-2025-70842 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The f... |
| CVE-2025-40948 | MEDIUM | 6.8 | 0.3% | May 12, 2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-65417 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page... |
| CVE-2025-65416 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. |
| CVE-2025-65415 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now