2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10656 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Au... |
| CVE-2025-50455 | CRITICAL | 9.1 | 0.6% | Jul 27, 2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp... |
| CVE-2025-71389 | CRITICAL | 10 | — | Jul 23, 2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio... |
| CVE-2025-50329 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec... |
| CVE-2025-66390 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ... |
| CVE-2025-51677 | CRITICAL | 9.1 | 0.4% | Jul 17, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12... |
| CVE-2025-65720 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user... |
| CVE-2025-11698 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit... |
| CVE-2025-12012 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u... |
| CVE-2025-12011 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to ... |
| CVE-2025-58151 | CRITICAL | 9.4 | — | Jul 9, 2026 | varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ... |
| CVE-2025-58146 | CRITICAL | 9.4 | — | Jul 9, 2026 | There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica... |
| CVE-2025-27464 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27463 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27462 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-53830 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud... |
| CVE-2025-53827 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi... |
| CVE-2025-23351 | CRITICAL | 9 | — | Jul 1, 2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ... |
| CVE-2025-23350 | CRITICAL | 9 | — | Jul 1, 2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ... |
| CVE-2025-15646 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w... |
| CVE-2025-11919 | CRITICAL | 9.6 | — | Jun 26, 2026 | The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the... |
| CVE-2025-64152 | CRITICAL | 9.1 | — | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu... |
| CVE-2025-55017 | CRITICAL | 9.1 | — | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu... |
| CVE-2025-71338 | CRITICAL | 9.8 | 0.9% | Jun 25, 2026 | Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated at... |
| CVE-2025-71336 | CRITICAL | 9.8 | 0.7% | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now