2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70746HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime functi...
CVE-2025-29943MEDIUM4.6Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU ...
CVE-2025-68921HIGH7.8SteelSeries Nahimic 3 1.10.7 allows Directory traversal.
CVE-2025-15104MEDIUM5.3Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb...
CVE-2025-14894CRITICAL9.8Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p...
CVE-2025-14510CRITICAL9.2Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi...
CVE-2025-14435MEDIUM6.5Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API er...
CVE-2025-68675HIGH7.5In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy U...
CVE-2025-68438HIGH7.5In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length...
CVE-2025-59870CRITICAL9.8HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secr...
CVE-2025-14844HIGH7.5The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up...
CVE-2025-60021CRITICAL9.8Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all ...
CVE-2025-14822MEDIUM6.5Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica...
CVE-2025-14757MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions ...
CVE-2025-12007HIGH8.4There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up...
CVE-2025-12006HIGH7.2There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up...
CVE-2025-14375MEDIUM6.1The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec...
CVE-2025-14853MEDIUM4.3The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1....
CVE-2025-14793MEDIUM5The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u...
CVE-2025-15527MEDIUM4.3The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 ...
CVE-2025-15526MEDIUM5.3The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi...
CVE-2025-15370MEDIUM4.3The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D...
CVE-2025-14982MEDIUM4.3The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu...
CVE-2025-14384MEDIUM4.3The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ...
CVE-2025-12957HIGH8.8The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now