2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45806 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar... |
| CVE-2025-9484 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.1... |
| CVE-2025-30650 | MEDIUM | 6.7 | 0.1% | Apr 8, 2026 | A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a... |
| CVE-2025-57175 | MEDIUM | 6.8 | 0.1% | Apr 8, 2026 | Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password. |
| CVE-2025-14243 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum... |
| CVE-2025-58713 | MEDIUM | 6.4 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f... |
| CVE-2025-57854 | MEDIUM | 6.4 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from... |
| CVE-2025-57853 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi... |
| CVE-2025-57851 | MEDIUM | 6.7 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f... |
| CVE-2025-57847 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th... |
| CVE-2025-1794 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers... |
| CVE-2025-14732 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-20628 | MEDIUM | 6.9 | 0.2% | Apr 7, 2026 | An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w... |
| CVE-2025-14858 | MEDIUM | 5.1 | 0.1% | Apr 7, 2026 | The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability... |
| CVE-2025-14857 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware ... |
| CVE-2025-70844 | MEDIUM | 6.1 | 0.3% | Apr 7, 2026 | yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco... |
| CVE-2025-14944 | MEDIUM | 5.3 | 0.6% | Apr 7, 2026 | The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2... |
| CVE-2025-24819 | MEDIUM | 5.7 | 0.2% | Apr 7, 2026 | Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter... |
| CVE-2025-15611 | MEDIUM | 5.4 | 0.1% | Apr 7, 2026 | The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function be... |
| CVE-2025-65116 | MEDIUM | 5.5 | 0.1% | Apr 7, 2026 | Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati... |
| CVE-2025-13044 | MEDIUM | 6.2 | 0.1% | Apr 7, 2026 | IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar... |
| CVE-2025-48651 | MEDIUM | 5.5 | 0.1% | Apr 6, 2026 | In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr... |
| CVE-2025-61166 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted ... |
| CVE-2025-47374 | MEDIUM | 6.5 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling. |
| CVE-2025-14938 | MEDIUM | 5.3 | 0.3% | Apr 4, 2026 | The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now