2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15263CRITICAL9.8A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/logi...
CVE-2025-65411HIGH7.5A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Servi...
CVE-2025-65409HIGH7.5A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Servic...
CVE-2025-56332CRITICAL9.1Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Defa...
CVE-2025-15262HIGH7.2A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admi...
CVE-2025-15258MEDIUM6.1A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the...
CVE-2025-69204HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-68950MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-68926CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC...
CVE-2025-68618HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-66848CRITICAL9.8JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier...
CVE-2025-66103MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io w...
CVE-2025-66094MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki y...
CVE-2025-65925MEDIUM6.5An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to...
CVE-2025-62128MEDIUM4.3Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc...
CVE-2025-62112MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings easy-property-listing...
CVE-2025-59129HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appointify Appoint...
CVE-2025-52835CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a W...
CVE-2025-15257CRITICAL9.8A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRo...
CVE-2025-15256CRITICAL9.8A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /gofo...
CVE-2025-67746MEDIUM4.3Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling...
CVE-2025-66080MEDIUM5.3Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-con...
CVE-2025-64528MEDIUM5.3Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who know...
CVE-2025-64190MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core...
CVE-2025-63027MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcreations907 WB...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now