2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26394MEDIUM4.8SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sani...
CVE-2025-22463HIGH7.3A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt t...
CVE-2025-22455HIGH7.8A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt st...
CVE-2025-49511HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery...
CVE-2025-49510MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce produc...
CVE-2025-49509MEDIUM5.3Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting ...
CVE-2025-49507CRITICAL9.8Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect...
CVE-2025-49455CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor...
CVE-2025-49454HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-4774MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdow...
CVE-2025-4577MEDIUM5.4The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-43701HIGH7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settin...
CVE-2025-43700HIGH7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted dat...
CVE-2025-43699MEDIUM5.3Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of requ...
CVE-2025-43698CRITICAL9.1Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec...
CVE-2025-43697HIGH7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted da...
CVE-2025-2918MEDIUM5.4The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mult...
CVE-2025-41657MEDIUM4.3Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerpri...
CVE-2025-40662HIGH7.5Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents...
CVE-2025-40661HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40660HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40659HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40658HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40657CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40656CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now