2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14369MEDIUM5.5dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting th...
CVE-2025-41084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are ...
CVE-2025-14533CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a...
CVE-2025-41768MEDIUM5.5An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to...
CVE-2025-66523MEDIUM6.1URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th...
CVE-2025-12573MEDIUM6.5The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al...
CVE-2025-14977HIGH8.1The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2025-14348MEDIUM5.3The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-14798MEDIUM5.3The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a...
CVE-2025-14351MEDIUM5.3The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...
CVE-2025-14978MEDIUM5.3The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W...
CVE-2025-15466MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d...
CVE-2025-69199MEDIUM6.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2025-69198MEDIUM6.5Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to ...
CVE-2025-55252CRITICAL9.8HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable pas...
CVE-2025-55250MEDIUM5.3HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail...
CVE-2025-55251CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-55249MEDIUM5.3HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may ...
CVE-2025-52661MEDIUM5.3HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,...
CVE-2025-52660CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-52659HIGH7.5HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit...
CVE-2025-68616HIGH7.5WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro...
CVE-2025-61684HIGH7.5Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a...
CVE-2025-11044HIGH8.9An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Run...
CVE-2025-11043CRITICAL9.1An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now