2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12012CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u...
CVE-2025-12011CRITICAL9.2A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to ...
CVE-2025-40945MEDIUM6.7A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),...
CVE-2025-8412LOW2A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa...
CVE-2025-15665MEDIUM5.4The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl...
CVE-2025-45869HIGH7.3LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti...
CVE-2025-6784HIGH8.8The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ...
CVE-2025-5017MEDIUM4.9The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’...
CVE-2025-13968MEDIUM6.4The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod...
CVE-2025-30008MEDIUM5.4HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users...
CVE-2025-30007HIGH8.8HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat...
CVE-2025-70796HIGH7.5An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc....
CVE-2025-12127——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-11977MEDIUM6.6The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo...
CVE-2025-45422HIGH8.1Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak...
CVE-2025-63579HIGH7.5Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu...
CVE-2025-58151CRITICAL9.4varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ...
CVE-2025-58146CRITICAL9.4There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica...
CVE-2025-27464CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27463CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27462CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-12506MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and ...
CVE-2025-3110HIGH7.5OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at...
CVE-2025-14785MEDIUM6.4The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...
CVE-2025-12799MEDIUM6.5A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now