2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14314HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit po...
CVE-2025-13498MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ...
CVE-2025-12976MEDIUM6.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-10019MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al...
CVE-2025-68463MEDIUM4.9Bio.Entrez in Biopython through 186 allows doctype XXE.
CVE-2025-68462LOW3.2Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump f...
CVE-2025-68459HIGH8.6RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injec...
CVE-2025-47387HIGH7.8Memory Corruption when processing IOCTLs for JPEG data without verification.
CVE-2025-47382HIGH7.8Memory corruption while loading an invalid firmware in boot loader.
CVE-2025-47372HIGH8.4Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
CVE-2025-47350HIGH7.8Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
CVE-2025-47325MEDIUM5.5Information disclosure while processing system calls with invalid parameters.
CVE-2025-47323HIGH7.8Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-47322HIGH7.8Memory corruption while handling IOCTL calls to set mode.
CVE-2025-47321HIGH7.8Memory corruption while copying packets received from unix clients.
CVE-2025-47320HIGH7.8Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-47319MEDIUM6.7Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-27063HIGH7.8Memory corruption during video playback when video session open fails with time out error.
CVE-2025-68461MEDIUM6.1Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani...
CVE-2025-68460HIGH7.5Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML sty...
CVE-2025-12885MEDIUM6.4The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-14856HIGH8.8A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function o...
CVE-2025-14841LOW3.3A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHand...
CVE-2025-14837HIGH7.2A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/sitecon...
CVE-2025-14202HIGH8.2A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now