2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61140CRITICAL9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVE-2025-58150HIGH8.8Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables...
CVE-2025-57283HIGH7.8The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile...
CVE-2025-14795MEDIUM4.3The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14865MEDIUM6.4The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-59901HIGH8.5Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoin...
CVE-2025-59900MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59899MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59898MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59897MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59896MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59895HIGH7.5Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulne...
CVE-2025-59894HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59893HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59892HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59891HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-26386HIGH7.1Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iST...
CVE-2025-15511MEDIUM5.3The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2025-14616MEDIUM4.3The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14386HIGH8.8The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ...
CVE-2025-14283MEDIUM6.4The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ...
CVE-2025-14063MEDIUM6.1The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p...
CVE-2025-41351MEDIUM6Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail...
CVE-2025-7740HIGH8.8Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attack...
CVE-2025-40554CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now