2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-56332CRITICAL9.1Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Defa...
CVE-2025-15262HIGH7.2A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admi...
CVE-2025-15258MEDIUM6.1A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the...
CVE-2025-69204HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-68950MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-68926CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC...
CVE-2025-68618HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-66848CRITICAL9.8JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier...
CVE-2025-66103MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io w...
CVE-2025-66094MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki y...
CVE-2025-65925MEDIUM6.5An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to...
CVE-2025-62128MEDIUM4.3Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc...
CVE-2025-62112MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings easy-property-listing...
CVE-2025-59129HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appointify Appoint...
CVE-2025-52835CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a W...
CVE-2025-15257CRITICAL9.8A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRo...
CVE-2025-15256CRITICAL9.8A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /gofo...
CVE-2025-67746MEDIUM4.3Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling...
CVE-2025-66080MEDIUM5.3Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-con...
CVE-2025-64528MEDIUM5.3Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who know...
CVE-2025-64190MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core...
CVE-2025-63027MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcreations907 WB...
CVE-2025-62746MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeFlavors Featur...
CVE-2025-61557HIGH7.5nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.
CVE-2025-15255CRITICAL9.8A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now