2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9315MEDIUM6.3An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determ...
CVE-2025-66004MEDIUM5.7A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd:...
CVE-2025-1161HIGH7.1Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem a...
CVE-2025-14087CRITICAL9.8A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a...
CVE-2025-14082LOW2.7A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information dis...
CVE-2025-13955CRITICAL9.3Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows atta...
CVE-2025-13954CRITICAL9.3Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori...
CVE-2025-12952HIGH8.7A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e...
CVE-2025-9571HIGH8.7A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa...
CVE-2025-13073HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13072HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13339HIGH7.5The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in...
CVE-2025-9056MEDIUM5.3Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized servic...
CVE-2025-67613Rejected reason: Not used
CVE-2025-67612Rejected reason: Not used
CVE-2025-67611Rejected reason: Not used
CVE-2025-67610Rejected reason: Not used
CVE-2025-67609Rejected reason: Not used
CVE-2025-67608Rejected reason: Not used
CVE-2025-67607Rejected reason: Not used
CVE-2025-67606Rejected reason: Not used
CVE-2025-67605Rejected reason: Not used
CVE-2025-13677MEDIUM4.9The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2...
CVE-2025-13613CRITICAL9.8The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, ...
CVE-2025-67507HIGH8.1Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now