2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14266LOW0.6CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administ...
CVE-2025-62690MEDIUM6.1Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re...
CVE-2025-62190MEDIUM4.3Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail...
CVE-2025-61736HIGH7.1Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the...
CVE-2025-14097HIGH7.2A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor...
CVE-2025-14096HIGH8.4A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi...
CVE-2025-13352LOW3Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identit...
CVE-2025-67895CRITICAL9.8Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you in...
CVE-2025-14095MEDIUM6.8A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi...
CVE-2025-14101HIGH7.1Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi...
CVE-2025-14347MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-14399MEDIUM4.3The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2025-12496MEDIUM4.9The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2025-14817MEDIUM6.5The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro...
CVE-2025-14061MEDIUM5.3The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C...
CVE-2025-13750MEDIUM4.3The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modif...
CVE-2025-11924HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj...
CVE-2025-14154MEDIUM6.1The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2025-64700MEDIUM5.1Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logg...
CVE-2025-59374CRITICAL9.8"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modificat...
CVE-2025-14385MEDIUM6.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve...
CVE-2025-13880MEDIUM6.5The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and...
CVE-2025-13861MEDIUM6.1The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scriptin...
CVE-2025-11901HIGH7An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760...
CVE-2025-11775MEDIUM4.8An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now