2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13217MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W...
CVE-2025-12689MEDIUM6.5Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p...
CVE-2025-67172HIGH7.2RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia...
CVE-2025-66924MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot...
CVE-2025-66923HIGH7.2A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot...
CVE-2025-65203HIGH7.1KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e...
CVE-2025-67285HIGH7.3A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using ...
CVE-2025-67165CRITICAL9.8An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
CVE-2025-67164CRITICAL9.9An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att...
CVE-2025-66921HIGH7.2A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re...
CVE-2025-65855MEDIUM6.6The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-...
CVE-2025-65185LOW2.8There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enume...
CVE-2025-53919HIGH7.8An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates ...
CVE-2025-53398HIGH7.8The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
CVE-2025-26381MEDIUM6.5Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati...
CVE-2025-20393CRITICAL10A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure...
CVE-2025-44005CRITICAL10An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without ...
CVE-2025-43873HIGH8.7Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the ...
CVE-2025-14727HIGH8.7A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v...
CVE-2025-14266LOW0.6CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administ...
CVE-2025-62690MEDIUM6.1Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re...
CVE-2025-62190MEDIUM4.3Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail...
CVE-2025-61736HIGH7.1Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the...
CVE-2025-14097HIGH7.2A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor...
CVE-2025-14096HIGH8.4A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now