2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14706CRITICAL9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/ht...
CVE-2025-14549HIGH8.1In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR ...
CVE-2025-13355HIGH7.1The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t...
CVE-2025-12684HIGH7.1The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t...
CVE-2025-11363MEDIUM5.3The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenti...
CVE-2025-14705CRITICAL9.8A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESE...
CVE-2025-14704CRITICAL9.8A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshel...
CVE-2025-67907——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67906. Reason: This candidate is a reservation d...
CVE-2025-67906CRITICAL9In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
CVE-2025-14703MEDIUM5.5A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /...
CVE-2025-14702MEDIUM4.4A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown function of the component b...
CVE-2025-13740MEDIUM6.4The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweigh...
CVE-2025-14699MEDIUM5.3A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown cod...
CVE-2025-14698MEDIUM4.4A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part o...
CVE-2025-14697LOW3.7A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3...
CVE-2025-14696MEDIUM5.3A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Aff...
CVE-2025-14695MEDIUM6.3A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the func...
CVE-2025-14694MEDIUM4.7A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/pos...
CVE-2025-14693MEDIUM6.2A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Hand...
CVE-2025-67901MEDIUM5.3openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEG...
CVE-2025-14692MEDIUM6.1A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authenticatio...
CVE-2025-67900HIGH8.1NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
CVE-2025-67899LOW2.9uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with...
CVE-2025-14691MEDIUM6.1A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authen...
CVE-2025-67898MEDIUM4.5MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now