2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13654HIGH7.5A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a conditio...
CVE-2025-59775HIGH7.5Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and M...
CVE-2025-55753HIGH7.5An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in defaul...
CVE-2025-13614HIGH8.1The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' s...
CVE-2025-12879HIGH8.8The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i...
CVE-2025-12851HIGH8.1The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,...
CVE-2025-12850HIGH7.5The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versio...
CVE-2025-12189HIGH8.8The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPres...
CVE-2025-12181HIGH8.8The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-12154HIGH8.8The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2025-12153HIGH8.8The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-13066HIGH8.8The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,...
CVE-2025-66564HIGH7.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest...
CVE-2025-66559HIGH8Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising it...
CVE-2025-14051HIGH8.8A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddres...
CVE-2025-13373HIGH8.7Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could al...
CVE-2025-66506HIGH7.5Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identit...
CVE-2025-66238HIGH7.4DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli...
CVE-2025-53704HIGH8.7The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc...
CVE-2025-1547HIGH7.2A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allo...
CVE-2025-1545HIGH7.5An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensi...
CVE-2025-13932HIGH8.3The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference ...
CVE-2025-12196HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2025-12195HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2025-12026HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now