2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59355MEDIUM6.5A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t...
CVE-2025-29847HIGH7.5A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and ...
CVE-2025-15539HIGH7.5A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notificati...
CVE-2025-15538HIGH7.8A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerabili...
CVE-2025-15537MEDIUM5.5A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::stri...
CVE-2025-15536MEDIUM5.5A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSeg...
CVE-2025-15535LOW3.3A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in t...
CVE-2025-15534HIGH7.8A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of t...
CVE-2025-15533HIGH7.8A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageF...
CVE-2025-15532HIGH7.5A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component ...
CVE-2025-15531MEDIUM5.5A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the fi...
CVE-2025-15530HIGH7.5A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_fo...
CVE-2025-8615MEDIUM6.4The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy ...
CVE-2025-14078MEDIUM5.3The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu...
CVE-2025-10484CRITICAL9.8The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B...
CVE-2025-14478HIGH7.5The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, ...
CVE-2025-12129MEDIUM5.3The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-12984MEDIUM4.9The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in...
CVE-2025-14029MEDIUM5.3The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-12825MEDIUM5.3The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-12168MEDIUM4.3The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-14463MEDIUM5.3The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, a...
CVE-2025-13725MEDIUM6.5The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to ar...
CVE-2025-15403CRITICAL9.8The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6...
CVE-2025-14632MEDIUM4.4The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted fi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now