2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0898MEDIUM6.5The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ...
CVE-2025-66593MEDIUM5.6An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary ...
CVE-2025-66592MEDIUM5.6An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use...
CVE-2025-52747HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox -...
CVE-2025-30028HIGH8.6A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2025-22741HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Fr...
CVE-2025-14713HIGH7.5An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0...
CVE-2025-13593MEDIUM5.6Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbi...
CVE-2025-13392CRITICAL9.8Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7...
CVE-2025-13167MEDIUM5.4Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functional...
CVE-2025-12686CRITICAL9.8Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStati...
CVE-2025-10466MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn...
CVE-2025-41670HIGH8.7A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating co...
CVE-2025-41669HIGH8.8The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloade...
CVE-2025-14481MEDIUM4.3The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi...
CVE-2025-15649MEDIUM5.5IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed...
CVE-2025-46307MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to acc...
CVE-2025-46284HIGH7A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An...
CVE-2025-46280MEDIUM5.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be ...
CVE-2025-43451MEDIUM5.5A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be ...
CVE-2025-43306HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta...
CVE-2025-43290MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma ...
CVE-2025-43289MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macO...
CVE-2025-68711LOW2.4AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker...
CVE-2025-68708LOW2.4SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now