2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66173MEDIUM6.2There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of auth...
CVE-2025-14449MEDIUM6.4The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo...
CVE-2025-14267MEDIUM4.9Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows d...
CVE-2025-13999HIGH7.2The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S...
CVE-2025-13754MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive ...
CVE-2025-13008HIGH8.6An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and ...
CVE-2025-13307HIGH7.2The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic....
CVE-2025-14546MEDIUM6.3Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope...
CVE-2025-68491Rejected reason: Not used
CVE-2025-68490Rejected reason: Not used
CVE-2025-68489Rejected reason: Not used
CVE-2025-68488Rejected reason: Not used
CVE-2025-68487Rejected reason: Not used
CVE-2025-68486Rejected reason: Not used
CVE-2025-68485Rejected reason: Not used
CVE-2025-68484Rejected reason: Not used
CVE-2025-68483Rejected reason: Not used
CVE-2025-14940CRITICAL9.8A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio...
CVE-2025-14939HIGH7.2A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the...
CVE-2025-67846MEDIUM6.5The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches ...
CVE-2025-67845MEDIUM5.4A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows rem...
CVE-2025-67844MEDIUM4.3The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository...
CVE-2025-67843CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15...
CVE-2025-67842MEDIUM5.4The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HT...
CVE-2025-52692HIGH8.8Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially craft...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now