2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64355MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem...
CVE-2025-64282MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in RadiusTheme Radius Blocks radius-blocks allows Exploit...
CVE-2025-64236CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse....
CVE-2025-64235MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows...
CVE-2025-63043MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid a...
CVE-2025-63002MEDIUM5.3Missing Authorization vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Exploiting Incorre...
CVE-2025-62998MEDIUM5Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Re...
CVE-2025-62961MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured ...
CVE-2025-62960MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrect...
CVE-2025-14896HIGH8.7due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an a...
CVE-2025-14884HIGH7.3A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the com...
CVE-2025-14879CRITICAL9.8A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange...
CVE-2025-68469LOW3.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14...
CVE-2025-68278HIGH8.8Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in...
CVE-2025-64724HIGH7.3Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with wo...
CVE-2025-64723MEDIUM4.4Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with ...
CVE-2025-63391Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-63390MEDIUM5.3An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fa...
CVE-2025-63389CRITICAL9.8A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ...
CVE-2025-63388CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f...
CVE-2025-63386CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en...
CVE-2025-14878CRITICAL9.8A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele...
CVE-2025-14877CRITICAL9.8A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file...
CVE-2025-14823MEDIUM5.3In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure...
CVE-2025-9787MEDIUM6.1Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now