2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4579HIGH7.2The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and...
CVE-2025-47783MEDIUM6.1Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an at...
CVE-2025-46836MEDIUM6.6net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operatin...
CVE-2025-32421LOW3.7Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-...
CVE-2025-29691MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29690MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29689MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29688MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29686MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-47889CRITICAL9.8In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" ...
CVE-2025-47888MEDIUM5.9Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for conne...
CVE-2025-47887MEDIUM4.3Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers wit...
CVE-2025-47886MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earl...
CVE-2025-47885HIGH8.8Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Hea...
CVE-2025-47884CRITICAL9.1In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentiall...
CVE-2025-44879HIGH7.5WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerabi...
CVE-2025-44024MEDIUM6.1Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exist...
CVE-2025-27891CRITICAL9.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-26783HIGH7.5An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330,...
CVE-2025-32363CRITICAL9.8mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization...
CVE-2025-25370MEDIUM4.6An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain...
CVE-2025-4641CRITICAL9.3Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on W...
CVE-2025-4640HIGH8.3Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default...
CVE-2025-33104HIGH7.6IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2025-2900HIGH7.5IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now