2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32968HIGH8.8XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it ...
CVE-2025-32966CRITICAL9.8DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE...
CVE-2025-21605HIGH7.5Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An un...
CVE-2025-46393MEDIUM5.3In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the renderi...
CVE-2025-45428CRITICAL9.8In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack ...
CVE-2025-45427CRITICAL9.8In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow ...
CVE-2025-43965HIGH7.5In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
CVE-2025-43716MEDIUM5.8A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to...
CVE-2025-2703MEDIUM6.8The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modif...
CVE-2025-42605CRITICAL9.3This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for ...
CVE-2025-42604MEDIUM6.9This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker...
CVE-2025-42603HIGH8.7This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the respo...
CVE-2025-42602HIGH8.2This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API end...
CVE-2025-42601HIGH8.2This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API...
CVE-2025-42600HIGH8.2This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password...
CVE-2025-1054MEDIUM6.4The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2025-3530HIGH7.5The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up t...
CVE-2025-3529HIGH8.2The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2025-2595MEDIUM5.3An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization templa...
CVE-2025-0618MEDIUM6.5A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec...
CVE-2025-1056MEDIUM6.5Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the ...
CVE-2025-0926HIGH7.3Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to ...
CVE-2025-46224Rejected reason: Not used
CVE-2025-46223Rejected reason: Not used
CVE-2025-46222Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now