2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15674 | LOW | 2.7 | — | Aug 6, 2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ... |
| CVE-2025-14779 | LOW | 3.8 | 0.2% | Aug 6, 2026 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet... |
| CVE-2025-13736 | LOW | 3.7 | — | Aug 6, 2026 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo... |
| CVE-2025-12627 | LOW | 2.4 | — | Aug 6, 2026 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated... |
| CVE-2025-15677 | LOW | 3.5 | — | Aug 5, 2026 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin... |
| CVE-2025-71402 | LOW | 2 | — | Aug 1, 2026 | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou... |
| CVE-2025-14562 | LOW | 3.1 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2025-59866 | LOW | 3.3 | — | Jul 17, 2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es... |
| CVE-2025-8412 | LOW | 2 | — | Jul 14, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa... |
| CVE-2025-15668 | LOW | 3.3 | 0.1% | Jul 6, 2026 | A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/i... |
| CVE-2025-15667 | LOW | 3.3 | — | Jul 6, 2026 | A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit... |
| CVE-2025-0824 | LOW | 3.7 | 0.1% | Jun 29, 2026 | Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue... |
| CVE-2025-15619 | LOW | 3.5 | 0.1% | Jun 23, 2026 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin... |
| CVE-2025-59382 | LOW | 1.2 | 0.3% | Jun 10, 2026 | QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version: |
| CVE-2025-12656 | LOW | 3.8 | 0.3% | Jun 6, 2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de... |
| CVE-2025-62338 | LOW | 3.3 | 0.1% | Jun 4, 2026 | HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized ... |
| CVE-2025-48616 | LOW | 3.3 | 0.1% | Jun 1, 2026 | In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning... |
| CVE-2025-68711 | LOW | 2.4 | 0.2% | May 26, 2026 | AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker... |
| CVE-2025-68708 | LOW | 2.4 | 0.2% | May 26, 2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the ... |
| CVE-2025-68710 | LOW | 2.4 | 0.2% | May 26, 2026 | Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with... |
| CVE-2025-71310 | LOW | 1.8 | 0.3% | May 26, 2026 | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scri... |
| CVE-2025-14575 | LOW | 1.8 | 0.1% | May 19, 2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (... |
| CVE-2025-52532 | LOW | 2 | 0.1% | May 15, 2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa... |
| CVE-2025-66660 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2025-62317 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now