2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64462HIGH7.8There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI...
CVE-2025-64461HIGH8.5There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. ...
CVE-2025-63757HIGH7.5Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
CVE-2025-1031HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Funct...
CVE-2025-1030HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. Soli...
CVE-2025-1029HIGH7.5Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants...
CVE-2025-14861HIGH8.8Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2025-14860CRITICAL9.8Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
CVE-2025-14744MEDIUM6.5Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten...
CVE-2025-65000MEDIUM5.3SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2...
CVE-2025-40898HIGH8.1A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio...
CVE-2025-40893MEDIUM6.1A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo...
CVE-2025-40892HIGH8.9A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-40891MEDIUM4.7A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val...
CVE-2025-14618MEDIUM4.3The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du...
CVE-2025-14437HIGH7.5The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2025-14277MEDIUM4.3The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version...
CVE-2025-13110MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-10910CRITICAL9.3A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online...
CVE-2025-40602MEDIUM6.6A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme...
CVE-2025-64997MEDIUM6.5Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view...
CVE-2025-14364HIGH8.8The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil...
CVE-2025-13730MEDIUM6.4The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op...
CVE-2025-13641HIGH8.8The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu...
CVE-2025-14874HIGH7.5A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now