2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-14322HIGH8Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed...
CVE-2025-14309HIGH7.5NULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2.
CVE-2025-14307HIGH8.1An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The c...
CVE-2025-14286HIGH7.5A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit...
CVE-2025-13662HIGH7.8Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to ...
CVE-2025-13661HIGH8Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write ...
CVE-2025-13659HIGH8.8Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a...
CVE-2025-13604HIGH7.2The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2025-13428HIGH7.2A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an ...
CVE-2025-13071HIGH7.1The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back ...
CVE-2025-12807HIGH8.7A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive data...
CVE-2025-12705HIGH7.2The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param...
CVE-2025-12381HIGH7.8Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P...
CVE-2025-10655HIGH8.8SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para...
CVE-2025-66204HIGH8.1WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in...
CVE-2025-65964HIGH8.8n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to...
CVE-2025-65271HIGH8.8Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te...
CVE-2025-14261HIGH7.1The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only...
CVE-2025-48625HIGH7In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen ...
CVE-2025-48606HIGH7.8In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi...
CVE-2025-65795HIGH7.5Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create ...
CVE-2025-65363HIGH7.2Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app...
CVE-2025-63721HIGH8.8HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit ...
CVE-2025-48639HIGH7.3In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking...
CVE-2025-48638HIGH7.8In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now