2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15506LOW3.3A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT...
CVE-2025-15505LOW2.4A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web...
CVE-2025-13393MEDIUM4.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2025-12379MEDIUM6.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-14555MEDIUM6.4The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-15504MEDIUM5.5A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa...
CVE-2025-14506MEDIUM6.4The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block...
CVE-2025-62235HIGH8.1Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could le...
CVE-2025-53477HIGH7.5NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T...
CVE-2025-53470LOW3.1Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo...
CVE-2025-52435HIGH7.5J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause ...
CVE-2025-15503CRITICAL9.8A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele...
CVE-2025-14976MEDIUM5.4The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2025-15502CRITICAL9.8A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ...
CVE-2025-14948MEDIUM5.3The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-14943MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2025-65091CRITICAL10XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t...
CVE-2025-65090MEDIUM5.3XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights ...
CVE-2025-61676MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-61674MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-13457HIGH7.5The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...
CVE-2025-68470MEDIUM6.5React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path ...
CVE-2025-61686CRITICAL9.1React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version...
CVE-2025-59057HIGH7.6React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 ...
CVE-2025-15501CRITICAL9.8A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now