2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13551HIGH8.8A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an un...
CVE-2025-13550HIGH8.8A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown functi...
CVE-2025-13549HIGH8.8A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNt...
CVE-2025-13548HIGH8.8A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects un...
CVE-2025-13547HIGH8.8A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the fi...
CVE-2025-13545HIGH7.2A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3....
CVE-2025-13526HIGH7.5The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,...
CVE-2025-13384HIGH7.5The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...
CVE-2025-65947HIGH8.7thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resour...
CVE-2025-65946HIGH8.1Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error...
CVE-2025-12888HIGH7.5Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler o...
CVE-2025-11931HIGH8.2Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a cal...
CVE-2025-65109HIGH8.5Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and...
CVE-2025-65106HIGH8.3LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1...
CVE-2025-65102HIGH8.7PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the inpu...
CVE-2025-11935HIGH7.5With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy...
CVE-2025-11087HIGH8.8The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up ...
CVE-2025-62626HIGH7.2Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned ...
CVE-2025-62609HIGH7.5MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault ...
CVE-2025-13132HIGH7.4This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) ap...
CVE-2025-13470HIGH7.7In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session K...
CVE-2025-12973HIGH7.2The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra...
CVE-2025-66095HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi...
CVE-2025-66073HIGH7.2Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue...
CVE-2025-66055HIGH7.2Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Obje...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now