2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66434HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th...
CVE-2025-65742HIGH8.2An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to...
CVE-2025-55901MEDIUM6.5TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_...
CVE-2025-55893MEDIUM6.5TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.
CVE-2025-11393HIGH8.7A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of...
CVE-2025-66963MEDIUM5.5An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in...
CVE-2025-66844CRITICAL9.1In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is ...
CVE-2025-66843MEDIUM5.4grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An...
CVE-2025-60786HIGH8.8A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb...
CVE-2025-14387MEDIUM6.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ...
CVE-2025-13888CRITICAL9.1A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system in...
CVE-2025-13824HIGH8.7A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard f...
CVE-2025-13823HIGH7.1A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received mult...
CVE-2025-34412——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulne...
CVE-2025-34411——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulne...
CVE-2025-34181HIGH8.7NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFIL...
CVE-2025-34180HIGH8.4NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and ...
CVE-2025-34179HIGH8.7NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gatew...
CVE-2025-14383HIGH7.5The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param...
CVE-2025-14156CRITICAL9.8The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and...
CVE-2025-14003MEDIUM4.3The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-13950MEDIUM5.3The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2025-13728MEDIUM6.4The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored...
CVE-2025-13610MEDIUM6.4The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-13608MEDIUM6.4The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now