2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3679CRITICAL9.8A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function ...
CVE-2025-31363MEDIUM6.5Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to...
CVE-2025-27936MEDIUM5.9Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enable...
CVE-2025-3678CRITICAL9.8A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk...
CVE-2025-3677MEDIUM5.3A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the functio...
CVE-2025-3104MEDIUM5.3The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and...
CVE-2025-3676CRITICAL9.8A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the f...
CVE-2025-3077MEDIUM5.4The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custo...
CVE-2025-27571MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived...
CVE-2025-27538LOW2.7Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when ...
CVE-2025-24839MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering ...
CVE-2025-0101MEDIUM6.5A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time li...
CVE-2025-3675MEDIUM5.3A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issu...
CVE-2025-3674MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this v...
CVE-2025-3247MEDIUM5.3The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via th...
CVE-2025-3668MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability...
CVE-2025-3667MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the...
CVE-2025-22018MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_...
CVE-2025-3666MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is...
CVE-2025-3698HIGH7.5Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage ris...
CVE-2025-3665MEDIUM6.9A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vul...
CVE-2025-3664MEDIUM6.9A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the f...
CVE-2025-3663HIGH8.2A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue a...
CVE-2025-3495CRITICAL9.8Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker ...
CVE-2025-2314MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now