2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41024MEDIUM5.4Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user in...
CVE-2025-40679MEDIUM5.1HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation ...
CVE-2025-40644MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla's QRGen. This vulnerability allows an attavker to execut...
CVE-2025-14369MEDIUM5.5dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting th...
CVE-2025-41084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are ...
CVE-2025-14533CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a...
CVE-2025-41768MEDIUM5.5An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to...
CVE-2025-66523MEDIUM6.1URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th...
CVE-2025-12573MEDIUM6.5The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al...
CVE-2025-14977HIGH8.1The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2025-14348MEDIUM5.3The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-14798MEDIUM5.3The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a...
CVE-2025-14351MEDIUM5.3The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...
CVE-2025-14978MEDIUM5.3The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W...
CVE-2025-15466MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d...
CVE-2025-69199MEDIUM6.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2025-69198MEDIUM6.5Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to ...
CVE-2025-55252CRITICAL9.8HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable pas...
CVE-2025-55250MEDIUM5.3HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail...
CVE-2025-55251CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-55249MEDIUM5.3HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may ...
CVE-2025-52661MEDIUM5.3HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,...
CVE-2025-52660CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-52659HIGH7.5HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit...
CVE-2025-68616HIGH7.5WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now