2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14744MEDIUM6.5Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten...
CVE-2025-65000MEDIUM5.3SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2...
CVE-2025-40898HIGH8.1A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio...
CVE-2025-40893MEDIUM6.1A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo...
CVE-2025-40892HIGH8.9A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-40891MEDIUM4.7A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val...
CVE-2025-14618MEDIUM4.3The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du...
CVE-2025-14437HIGH7.5The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2025-14277MEDIUM4.3The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version...
CVE-2025-13110MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-10910CRITICAL9.3A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online...
CVE-2025-40602MEDIUM6.6A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme...
CVE-2025-64997MEDIUM6.5Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view...
CVE-2025-14364HIGH8.8The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil...
CVE-2025-13730MEDIUM6.4The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op...
CVE-2025-13641HIGH8.8The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu...
CVE-2025-14874HIGH7.5A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t...
CVE-2025-6326HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-6324HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy ...
CVE-2025-67546MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret...
CVE-2025-66119HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ...
CVE-2025-66118HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Cl...
CVE-2025-66117HIGH7.5Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-66116HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ul...
CVE-2025-66104MEDIUM6.5Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now