2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12012 | CRITICAL | 9.2 | 0.4% | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u... |
| CVE-2025-12011 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to ... |
| CVE-2025-40945 | MEDIUM | 6.7 | 0.2% | Jul 14, 2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),... |
| CVE-2025-8412 | LOW | 2 | — | Jul 14, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa... |
| CVE-2025-15665 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl... |
| CVE-2025-45869 | HIGH | 7.3 | — | Jul 13, 2026 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti... |
| CVE-2025-6784 | HIGH | 8.8 | 0.5% | Jul 11, 2026 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ... |
| CVE-2025-5017 | MEDIUM | 4.9 | 0.3% | Jul 11, 2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’... |
| CVE-2025-13968 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod... |
| CVE-2025-30008 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users... |
| CVE-2025-30007 | HIGH | 8.8 | 2.1% | Jul 10, 2026 | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat... |
| CVE-2025-70796 | HIGH | 7.5 | — | Jul 10, 2026 | An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.... |
| CVE-2025-12127 | — | — | — | Jul 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-11977 | MEDIUM | 6.6 | 0.5% | Jul 10, 2026 | The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo... |
| CVE-2025-45422 | HIGH | 8.1 | 0.2% | Jul 9, 2026 | Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak... |
| CVE-2025-63579 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu... |
| CVE-2025-58151 | CRITICAL | 9.4 | — | Jul 9, 2026 | varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ... |
| CVE-2025-58146 | CRITICAL | 9.4 | — | Jul 9, 2026 | There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica... |
| CVE-2025-27464 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27463 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27462 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-12506 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and ... |
| CVE-2025-3110 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at... |
| CVE-2025-14785 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor... |
| CVE-2025-12799 | MEDIUM | 6.5 | 0.2% | Jul 7, 2026 | A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now