2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11087HIGH8.8The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up ...
CVE-2025-62626HIGH7.2Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned ...
CVE-2025-62609HIGH7.5MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault ...
CVE-2025-13132HIGH7.4This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) ap...
CVE-2025-13470HIGH7.7In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session K...
CVE-2025-12973HIGH7.2The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra...
CVE-2025-66095HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi...
CVE-2025-66073HIGH7.2Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue...
CVE-2025-66055HIGH7.2Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Obje...
CVE-2025-40210HIGH7.5In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operation...
CVE-2025-13138HIGH7.5The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec...
CVE-2025-12160HIGH7.2The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p...
CVE-2025-13156HIGH8.8The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi...
CVE-2025-13322HIGH8.1The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2025-13159HIGH7.1The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG ...
CVE-2025-12138HIGH8.8The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida...
CVE-2025-12135HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi...
CVE-2025-11985HIGH8.8The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc...
CVE-2025-64695HIGH8.4Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitr...
CVE-2025-58097HIGH7.8The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u...
CVE-2025-64751HIGH8.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-62164HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor...
CVE-2025-64660HIGH8Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne...
CVE-2025-36072HIGH8.8IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi...
CVE-2025-61138HIGH7.5Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now