2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27851CRITICAL9.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac...
CVE-2025-27850HIGH7.5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics pac...
CVE-2025-32425MEDIUM5.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2025-29338MEDIUM5.6NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff...
CVE-2025-28344HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2025-14767MEDIUM5.5The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2025-14033MEDIUM5.3The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-11159HIGH7.2Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul...
CVE-2025-9989MEDIUM4.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-9988MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat...
CVE-2025-9987MEDIUM5.3The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2025-14755MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct...
CVE-2025-62627HIGH7.2An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ...
CVE-2025-62624HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-62623HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-61972HIGH8.5Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma...
CVE-2025-61971MEDIUM5.9Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf...
CVE-2025-15463MEDIUM6.5The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers...
CVE-2025-65088HIGH7.8An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions...
CVE-2025-65087HIGH7.8An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions...
CVE-2025-65086HIGH7.8An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version...
CVE-2025-67604MEDIUM5.3A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0...
CVE-2025-53870MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2025-53844HIGH8.8A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now