2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66388MEDIUM6.5A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secr...
CVE-2025-37732MEDIUM5.4Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us...
CVE-2025-37731HIGH7.4Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica...
CVE-2025-14714MEDIUM6.5An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the T...
CVE-2025-11670MEDIUM4.3Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is e...
CVE-2025-14711CRITICAL9.8A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability a...
CVE-2025-14710CRITICAL9.8A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects ...
CVE-2025-14709CRITICAL9.8A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functi...
CVE-2025-14708HIGH7.5A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit...
CVE-2025-14023MEDIUM4.3LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app...
CVE-2025-14022MEDIUM6.8LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an ...
CVE-2025-14021MEDIUM4.3The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could all...
CVE-2025-14020MEDIUM4.3LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the ful...
CVE-2025-14019MEDIUM4.7LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific l...
CVE-2025-14712HIGH8.7Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil...
CVE-2025-14707CRITICAL9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbi...
CVE-2025-14706CRITICAL9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/ht...
CVE-2025-14549HIGH8.1In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR ...
CVE-2025-13355HIGH7.1The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t...
CVE-2025-12684HIGH7.1The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t...
CVE-2025-11363MEDIUM5.3The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenti...
CVE-2025-14705CRITICAL9.8A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESE...
CVE-2025-14704CRITICAL9.8A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshel...
CVE-2025-67907Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67906. Reason: This candidate is a reservation d...
CVE-2025-67906CRITICAL9In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now