2025 CVE Vulnerabilities

45,323 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13917HIGH7WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereb...
CVE-2025-70336MEDIUM4.8A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote atta...
CVE-2025-69517HIGH8.8An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject ar...
CVE-2025-61140CRITICAL9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVE-2025-58150HIGH8.8Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables...
CVE-2025-57283HIGH7.8The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile...
CVE-2025-14795MEDIUM4.3The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14865MEDIUM6.4The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-59901HIGH8.5Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoin...
CVE-2025-59900MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59899MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59898MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59897MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59896MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59895HIGH7.5Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulne...
CVE-2025-59894HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59893HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59892HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-59891HIGH8Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10....
CVE-2025-26386HIGH7.1Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iST...
CVE-2025-15511MEDIUM5.3The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2025-14616MEDIUM4.3The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14386HIGH8.8The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ...
CVE-2025-14283MEDIUM6.4The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ...
CVE-2025-14063MEDIUM6.1The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now