2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69267MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru...
CVE-2025-52694CRITICAL9.8Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb...
CVE-2025-68493HIGH8.1Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 befo...
CVE-2025-15506LOW3.3A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT...
CVE-2025-15505LOW2.4A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web...
CVE-2025-13393MEDIUM4.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2025-12379MEDIUM6.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-14555MEDIUM6.4The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-15504MEDIUM5.5A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa...
CVE-2025-14506MEDIUM6.4The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block...
CVE-2025-62235HIGH8.1Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could le...
CVE-2025-53477HIGH7.5NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T...
CVE-2025-53470LOW3.1Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo...
CVE-2025-52435HIGH7.5J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause ...
CVE-2025-15503CRITICAL9.8A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele...
CVE-2025-14976MEDIUM5.4The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2025-15502CRITICAL9.8A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ...
CVE-2025-14948MEDIUM5.3The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-14943MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2025-65091CRITICAL10XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t...
CVE-2025-65090MEDIUM5.3XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights ...
CVE-2025-61676MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-61674MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-13457HIGH7.5The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...
CVE-2025-68470MEDIUM6.5React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now