2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-63387HIGH7.5Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to th...
CVE-2025-59949MEDIUM6.5FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vuln...
CVE-2025-56157CRITICAL9.8Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file inclu...
CVE-2025-14885HIGH8.8A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file ...
CVE-2025-14739MEDIUM6.8Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the a...
CVE-2025-14738HIGH7.5Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download th...
CVE-2025-14737HIGH8Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbi...
CVE-2025-66058MEDIUM6.5Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectl...
CVE-2025-64355MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem...
CVE-2025-64282MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in RadiusTheme Radius Blocks radius-blocks allows Exploit...
CVE-2025-64236CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse....
CVE-2025-64235MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows...
CVE-2025-63043MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid a...
CVE-2025-63002MEDIUM5.3Missing Authorization vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Exploiting Incorre...
CVE-2025-62998MEDIUM5Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Re...
CVE-2025-62961MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured ...
CVE-2025-62960MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrect...
CVE-2025-14896HIGH8.7due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an a...
CVE-2025-14884HIGH7.2A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the com...
CVE-2025-14879CRITICAL9.8A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange...
CVE-2025-68469LOW3.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14...
CVE-2025-68278HIGH8.8Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in...
CVE-2025-64724HIGH7.3Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with wo...
CVE-2025-64723MEDIUM4.4Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with ...
CVE-2025-63391——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now