2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13352LOW3Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identit...
CVE-2025-67895CRITICAL9.8Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you in...
CVE-2025-14095MEDIUM6.8A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi...
CVE-2025-14101HIGH7.1Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi...
CVE-2025-14347MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-14399MEDIUM4.3The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2025-12496MEDIUM4.9The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2025-14817MEDIUM6.5The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro...
CVE-2025-14061MEDIUM5.3The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C...
CVE-2025-13750MEDIUM4.3The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modif...
CVE-2025-11924HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj...
CVE-2025-14154MEDIUM6.1The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2025-64700MEDIUM5.1Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logg...
CVE-2025-59374CRITICAL9.8"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modificat...
CVE-2025-14385MEDIUM6.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve...
CVE-2025-13880MEDIUM6.5The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and...
CVE-2025-13861MEDIUM6.1The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scriptin...
CVE-2025-11901HIGH7An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760...
CVE-2025-11775MEDIUM4.8An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by ...
CVE-2025-14305HIGH8.5ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replac...
CVE-2025-14304HIGH7Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanis...
CVE-2025-13977MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2025-14303HIGH7Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not prop...
CVE-2025-14302HIGH7Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not...
CVE-2025-14801MEDIUM4.8A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now