2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13764CRITICAL9.8The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16...
CVE-2025-11467MEDIUM5.8The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2025-67720MEDIUM6.5Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames...
CVE-2025-67719HIGH8.5Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have passw...
CVE-2025-67718HIGH8.7Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through...
CVE-2025-67717MEDIUM4.3ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 discl...
CVE-2025-67716MEDIUM5.7The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through ...
CVE-2025-67713MEDIUM6.1Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs...
CVE-2025-67648MEDIUM6.1Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XS...
CVE-2025-67646LOW3.5TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do...
CVE-2025-67644HIGH7.8LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2025-67514Rejected reason: Vulnerability is dependency-based.
CVE-2025-67512Rejected reason: The vulnerability is dependency-based.
CVE-2025-67511CRITICAL9.6Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automat...
CVE-2025-67513MEDIUM6.9FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and ...
CVE-2025-67510CRITICAL9.4Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool exe...
CVE-2025-67509HIGH8.2Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which...
CVE-2025-67505HIGH8.4Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race ...
CVE-2025-67490MEDIUM5.4The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.1...
CVE-2025-13923Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12731Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-66628HIGH7.5ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the T...
CVE-2025-66474HIGH8.8XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-66473HIGH7.5XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 ...
CVE-2025-66472MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-mi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now