2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66499HIGH7.8A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft...
CVE-2025-66498HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66497HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66496HIGH7.8A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch...
CVE-2025-66495HIGH7.8A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1...
CVE-2025-66494HIGH7.8A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on...
CVE-2025-66493HIGH7.8A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,...
CVE-2025-66174MEDIUM6.8There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of ...
CVE-2025-66173MEDIUM6.2There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of auth...
CVE-2025-14449MEDIUM6.4The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo...
CVE-2025-14267MEDIUM4.9Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows d...
CVE-2025-13999HIGH7.2The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S...
CVE-2025-13754MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive ...
CVE-2025-13008HIGH8.6An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and ...
CVE-2025-13307HIGH7.2The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic....
CVE-2025-14546MEDIUM6.3Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope...
CVE-2025-68491——Rejected reason: Not used
CVE-2025-68490——Rejected reason: Not used
CVE-2025-68489——Rejected reason: Not used
CVE-2025-68488——Rejected reason: Not used
CVE-2025-68487——Rejected reason: Not used
CVE-2025-68486——Rejected reason: Not used
CVE-2025-68485——Rejected reason: Not used
CVE-2025-68484——Rejected reason: Not used
CVE-2025-68483——Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now