2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15100HIGH8.8The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including...
CVE-2025-15027CRITICAL9.8The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including...
CVE-2025-15564MEDIUM5.5A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::...
CVE-2025-15477MEDIUM6.5The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr...
CVE-2025-15476MEDIUM4.3The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-15491MEDIUM5.5The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate...
CVE-2025-15267MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion...
CVE-2025-13463MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in a...
CVE-2025-12803MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor...
CVE-2025-12159MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_conte...
CVE-2025-31990MEDIUM6.8Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) att...
CVE-2025-68621HIGH7.4Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person...
CVE-2025-15320LOW3.3Tanium addressed a denial of service vulnerability in Tanium Client.
CVE-2025-69216MEDIUM6.5OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au...
CVE-2025-69214HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ...
CVE-2025-69212HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri...
CVE-2025-70963HIGH7.6Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived ...
CVE-2025-64175HIGH8.8Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not...
CVE-2025-64111CRITICAL9.8Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-...
CVE-2025-13523MEDIUM5.4Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rend...
CVE-2025-13818MEDIUM6.7Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
CVE-2025-10753MEDIUM5.3The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions ...
CVE-2025-15566HIGH8.8A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress ...
CVE-2025-68458LOW3.7Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTT...
CVE-2025-68157LOW3.7Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTT...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now