2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34442HIGH7.5AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in...
CVE-2025-34441HIGH7.5AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response...
CVE-2025-34440MEDIUM6.1AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire...
CVE-2025-34439MEDIUM6.1AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet...
CVE-2025-34438HIGH8.1AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi...
CVE-2025-34437HIGH8.8AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The...
CVE-2025-34436HIGH8.8AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due...
CVE-2025-34435MEDIUM6.5AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated...
CVE-2025-34434CRITICAL9.1AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele...
CVE-2025-14760MEDIUM6Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro...
CVE-2025-14759MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t...
CVE-2025-67174HIGH7.5A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ...
CVE-2025-67173MEDIUM6.8A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar...
CVE-2025-67171HIGH7.5Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d...
CVE-2025-67170MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the...
CVE-2025-67168MEDIUM5.3RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
CVE-2025-66953HIGH8.8CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co...
CVE-2025-66395HIGH8.8ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-62521CRITICAL9.8ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio...
CVE-2025-14828Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-14081MEDIUM4.3The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl...
CVE-2025-13537MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri...
CVE-2025-13326LOW3.9Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged f...
CVE-2025-13324LOW3.7Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to...
CVE-2025-13321LOW3.3Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now