2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14358HIGH7.5Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly...
CVE-2025-14017MEDIUM6.3When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver...
CVE-2025-13504HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Real Est...
CVE-2025-13034MEDIUM5.9When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu...
CVE-2025-12551HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins ListingH...
CVE-2025-12550HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-12549HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-13679MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2025-14275MEDIUM6.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2025-12640MEDIUM4.3The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul...
CVE-2025-15346CRITICAL9.3A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client ...
CVE-2025-69262HIGH7.8pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment...
CVE-2025-62224LOW3.5User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke...
CVE-2025-69264CRITICAL9.8pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during ...
CVE-2025-69263HIGH8.8pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the l...
CVE-2025-69222HIGH8.1LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF...
CVE-2025-13151HIGH7.5Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resultin...
CVE-2025-12776MEDIUM5.4The Report Builder component of the application stores user input directly in a web page and displays it to other users,...
CVE-2025-69255MEDIUM4RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g...
CVE-2025-69221MEDIUM4.3LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que...
CVE-2025-69220MEDIUM5.9LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file...
CVE-2025-68705CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai...
CVE-2025-66620HIGH7.2An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An...
CVE-2025-64305HIGH7.1MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend...
CVE-2025-61939MEDIUM4.4An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now