2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14450MEDIUM6.5The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2025-14075MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-12718MEDIUM5.8The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6...
CVE-2025-12002MEDIUM5.9The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including...
CVE-2025-5489Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5102Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-56451MEDIUM6.1Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete...
CVE-2025-15529HIGH7.5A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_...
CVE-2025-15528HIGH7.5A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the...
CVE-2025-69581MEDIUM5.5An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i...
CVE-2025-68924HIGH7.5In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a...
CVE-2025-62291HIGH8.1In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted ...
CVE-2025-61873LOW2.6Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor...
CVE-2025-48647HIGH7.8In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope...
CVE-2025-15032HIGH7.4Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof ...
CVE-2025-51602MEDIUM4.8mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01...
CVE-2025-43904MEDIUM4.2In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user ...
CVE-2025-43508MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ...
CVE-2025-31510HIGH7.2In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web...
CVE-2025-31186LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to...
CVE-2025-24531MEDIUM6.7In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a...
CVE-2025-24528HIGH7.1In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update...
CVE-2025-24090LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ...
CVE-2025-24089MEDIUM5.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ...
CVE-2025-71020HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now