2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2571MEDIUM4.2Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth c...
CVE-2025-1792LOW3.1Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for g...
CVE-2025-0602HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DE...
CVE-2025-4598MEDIUM4.7A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace...
CVE-2025-48331HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter wooc...
CVE-2025-4433HIGH8.8Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrativ...
CVE-2025-40909MEDIUM5.9Perl threads have a working directory race condition where file operations may target unintended paths. If a directory ...
CVE-2025-2500CRITICAL9.1A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an...
CVE-2025-1484MEDIUM6.5A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploite...
CVE-2025-5190HIGH8.8The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is...
CVE-2025-4944MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-4597MEDIUM6.5The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-1763HIGH8.7An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass...
CVE-2025-5235MEDIUM5.4The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ paramete...
CVE-2025-5142MEDIUM6.5The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-4636HIGH7.8Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains co...
CVE-2025-4635MEDIUM6.6A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to ...
CVE-2025-4634MEDIUM4.1The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privile...
CVE-2025-4633MEDIUM6.5Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor...
CVE-2025-48912MEDIUM6.5An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injec...
CVE-2025-48334MEDIUM4.3Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro woo-slider-pro-drag-drop-slider-builder-for-woocom...
CVE-2025-5236MEDIUM5.4The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ par...
CVE-2025-4431MEDIUM4.3The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2025-4943MEDIUM5.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-...
CVE-2025-48936HIGH8.8Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now