2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13955CRITICAL9.3Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows atta...
CVE-2025-13954CRITICAL9.3Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori...
CVE-2025-12952HIGH8.7A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e...
CVE-2025-9571HIGH8.7A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa...
CVE-2025-13073HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13072HIGH7.1The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting...
CVE-2025-13339HIGH7.5The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in...
CVE-2025-9056MEDIUM5.3Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized servic...
CVE-2025-67613——Rejected reason: Not used
CVE-2025-67612——Rejected reason: Not used
CVE-2025-67611——Rejected reason: Not used
CVE-2025-67610——Rejected reason: Not used
CVE-2025-67609——Rejected reason: Not used
CVE-2025-67608——Rejected reason: Not used
CVE-2025-67607——Rejected reason: Not used
CVE-2025-67606——Rejected reason: Not used
CVE-2025-67605——Rejected reason: Not used
CVE-2025-13677MEDIUM4.9The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2...
CVE-2025-13613CRITICAL9.8The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, ...
CVE-2025-67507HIGH8.1Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont...
CVE-2025-67506CRITICAL9.8PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0....
CVE-2025-67485MEDIUM5.3mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se...
CVE-2025-67503——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2025-67502MEDIUM6.1Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t...
CVE-2025-67501HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now