2025 CVE Vulnerabilities

45,160 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14388CRITICAL9.8The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all ...
CVE-2025-14163MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14155MEDIUM5.3The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthor...
CVE-2025-12934HIGH8.1The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification o...
CVE-2025-68655Rejected reason: Not used
CVE-2025-68654Rejected reason: Not used
CVE-2025-68653Rejected reason: Not used
CVE-2025-68652Rejected reason: Not used
CVE-2025-68651Rejected reason: Not used
CVE-2025-68650Rejected reason: Not used
CVE-2025-67743MEDIUM6.5Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1...
CVE-2025-15034CRITICAL9.8A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the f...
CVE-2025-68615CRITICAL9.8net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted pac...
CVE-2025-68614MEDIUM5.4LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule A...
CVE-2025-68480MEDIUM5.3Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions fro...
CVE-2025-68476HIGH8.2KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Re...
CVE-2025-68475HIGH7.5Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7....
CVE-2025-67436MEDIUM6.5Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inj...
CVE-2025-65857HIGH7.5An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetS...
CVE-2025-65856CRITICAL9.8Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21....
CVE-2025-34458HIGH8.7wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vul...
CVE-2025-34457HIGH8.7wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 694c954, contain a stack-based buffer over...
CVE-2025-66736HIGH7.1youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does n...
CVE-2025-66735HIGH7.5youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does n...
CVE-2025-65817HIGH8.8LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now