2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48444MEDIUM5.3Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl...
CVE-2025-48013MEDIUM5.3Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl...
CVE-2025-3473MEDIUM6.7IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inhe...
CVE-2025-0163MEDIUM5.3IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames...
CVE-2025-4922HIGH8.1Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and...
CVE-2025-4605MEDIUM6.6A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnera...
CVE-2025-40914CRITICAL9.8Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a ...
CVE-2025-35941MEDIUM5.5A password is exposed locally.
CVE-2025-32711HIGH7.5Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2025-5144MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ paramete...
CVE-2025-5986MEDIUM6.5A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's de...
CVE-2025-5687HIGH7.8A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects M...
CVE-2025-49710CRITICAL9.8An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir...
CVE-2025-49709CRITICAL9.8Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
CVE-2025-3302HIGH7.2The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ ...
CVE-2025-4573MEDIUM4.1Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LD...
CVE-2025-4128MEDIUM4.3Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowi...
CVE-2025-4315HIGH8.8The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all vers...
CVE-2025-41663CRITICAL9.8For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman...
CVE-2025-41662Rejected reason: CVE-2025-41662 is considered redundant or unnecessary and thus should be withdrawn. Instead, a new CVE ...
CVE-2025-41661HIGH8.8An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack o...
CVE-2025-26412MEDIUM6.8The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with ...
CVE-2025-5991LOW2.1There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/...
CVE-2025-29756HIGH8.3SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the us...
CVE-2025-5395HIGH8.8The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now