2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14828——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-14081MEDIUM4.3The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl...
CVE-2025-13537MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri...
CVE-2025-13326LOW3.9Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged f...
CVE-2025-13324LOW3.7Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to...
CVE-2025-13321LOW3.3Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser...
CVE-2025-13217MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W...
CVE-2025-12689MEDIUM6.5Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p...
CVE-2025-67172HIGH7.2RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia...
CVE-2025-66924MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot...
CVE-2025-66923HIGH7.2A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot...
CVE-2025-65203HIGH7.1KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e...
CVE-2025-67285HIGH7.3A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using ...
CVE-2025-67165CRITICAL9.8An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
CVE-2025-67164CRITICAL9.9An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att...
CVE-2025-66921HIGH7.2A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re...
CVE-2025-65855MEDIUM6.6The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-...
CVE-2025-65185LOW2.8There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enume...
CVE-2025-53919HIGH7.8An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates ...
CVE-2025-53398HIGH7.8The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
CVE-2025-26381MEDIUM6.5Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati...
CVE-2025-20393CRITICAL10A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure...
CVE-2025-44005CRITICAL10An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without ...
CVE-2025-43873HIGH8.7Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the ...
CVE-2025-14727HIGH8.7A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now