2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13020HIGH8.8Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thu...
CVE-2025-13019HIGH8.1Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5,...
CVE-2025-13018HIGH8.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunde...
CVE-2025-13017HIGH8.1Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR ...
CVE-2025-13016HIGH7.5Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Fir...
CVE-2025-13014HIGH8.8Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR...
CVE-2025-13012HIGH7.5Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 11...
CVE-2025-10918HIGH7.1Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticate...
CVE-2025-11959HIGH8.1Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor v...
CVE-2025-9223HIGH8.8Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection v...
CVE-2025-11862HIGH8.4A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and de...
CVE-2025-11697HIGH8.9A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability a...
CVE-2025-11696HIGH8.9A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. ...
CVE-2025-11085HIGH8.6A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in t...
CVE-2025-11084HIGH7.6A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a val...
CVE-2025-10161HIGH7.3Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on ...
CVE-2025-12846HIGH8.8The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a...
CVE-2025-10714HIGH8.4AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala...
CVE-2025-11855HIGH7.5The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportReques...
CVE-2025-11307HIGH8.8The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJA...
CVE-2025-12637HIGH8.8The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f...
CVE-2025-11521HIGH8.1The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to i...
CVE-2025-11451HIGH7.5The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i...
CVE-2025-11168HIGH8.8The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5...
CVE-2025-42940HIGH7.5SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 da...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now