2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32750HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2025-11954HIGH8Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S...
CVE-2025-31985MEDIUM6.5HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-31973CRITICAL9.8HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd...
CVE-2025-33255CRITICAL9.8NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial...
CVE-2025-15369MEDIUM5.3The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due...
CVE-2025-15645MEDIUM5.1Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t...
CVE-2025-57798MEDIUM5.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1...
CVE-2025-61081Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-70950HIGH7.3An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
CVE-2025-51427HIGH7.3An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t...
CVE-2025-40904MEDIUM5.4A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an...
CVE-2025-40903MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid...
CVE-2025-40902MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p...
CVE-2025-40901MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation...
CVE-2025-40900MEDIUM5.1An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-14575LOW1.8An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (...
CVE-2025-15609HIGH7.5The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow...
CVE-2025-65954MEDIUM6.1SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel...
CVE-2025-57282HIGH8.8ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-56352HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri...
CVE-2025-4202MEDIUM4.3The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo...
CVE-2025-67031MEDIUM6.3ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera...
CVE-2025-67437MEDIUM6.5Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a...
CVE-2025-14972MEDIUM4.1* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now