2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12833MEDIUM4.3The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2025-12087MEDIUM4.3The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i...
CVE-2025-54983MEDIUM5.2A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under sp...
CVE-2025-43205MEDIUM4An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18...
CVE-2025-40760MEDIUM6.8A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly ...
CVE-2025-12748MEDIUM5.5A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files w...
CVE-2025-61845MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61844MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61843MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61842MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory expos...
CVE-2025-61841MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61840MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-62453MEDIUM5Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to by...
CVE-2025-62449MEDIUM6.8Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extens...
CVE-2025-62214MEDIUM6.7Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize...
CVE-2025-62209MEDIUM5.5Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in...
CVE-2025-62208MEDIUM5.5Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in...
CVE-2025-62206MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize...
CVE-2025-60728MEDIUM4.3Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a n...
CVE-2025-60723MEDIUM6.3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an...
CVE-2025-60722MEDIUM6.5Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori...
CVE-2025-60708MEDIUM6.5Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
CVE-2025-60706MEDIUM5.5Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2025-59513MEDIUM5.5Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca...
CVE-2025-59510MEDIUM5.5Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now