2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53346 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2025-53302 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constraine... |
| CVE-2025-52766 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-5085 | MEDIUM | 5.5 | 0.2% | Jun 2, 2026 | The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al... |
| CVE-2025-59614 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory Corruption when sending random number generator command with insufficient output buffer size. |
| CVE-2025-59613 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. |
| CVE-2025-59612 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory corruption in windows drivers while sending incorrect trusted application request |
| CVE-2025-59611 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory corruption in diagnostic services due to absence of input validation |
| CVE-2025-59610 | MEDIUM | 6.4 | 0.1% | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa... |
| CVE-2025-59609 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. |
| CVE-2025-59601 | MEDIUM | 6.5 | 0.1% | Jun 1, 2026 | Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized... |
| CVE-2025-48648 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This cou... |
| CVE-2025-60495 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box befo... |
| CVE-2025-60486 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows at... |
| CVE-2025-60485 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before... |
| CVE-2025-60483 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Pro... |
| CVE-2025-60481 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.0... |
| CVE-2025-55664 | MEDIUM | 5.5 | 0.2% | Jun 1, 2026 | A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to ... |
| CVE-2025-12714 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due ... |
| CVE-2025-14042 | MEDIUM | 6.4 | 0.2% | May 29, 2026 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-48977 | MEDIUM | 6.5 | 0.5% | May 28, 2026 | Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the ... |
| CVE-2025-67903 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. |
| CVE-2025-70116 | MEDIUM | 4.3 | 0.4% | May 27, 2026 | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can r... |
| CVE-2025-68712 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp... |
| CVE-2025-71312 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now