2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14286HIGH7.5A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit...
CVE-2025-14284MEDIUM6.1Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit...
CVE-2025-13662HIGH7.8Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to ...
CVE-2025-13661HIGH8Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write ...
CVE-2025-13659HIGH8.8Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a...
CVE-2025-13642MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2025-13604HIGH7.2The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2025-13428HIGH7.2A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an ...
CVE-2025-13071HIGH7.1The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back ...
CVE-2025-13070MEDIUM6.6The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener...
CVE-2025-13031MEDIUM5.9The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c...
CVE-2025-12807HIGH8.7A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive data...
CVE-2025-12705HIGH7.2The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param...
CVE-2025-12558MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2025-12504CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UN...
CVE-2025-12381HIGH7.8Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P...
CVE-2025-11022CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This ...
CVE-2025-10876MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft...
CVE-2025-10655HIGH8.8SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para...
CVE-2025-10573MEDIUM6.1Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute ...
CVE-2025-66491MEDIUM5.9Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in...
CVE-2025-66490MEDIUM6.5Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests us...
CVE-2025-66481CRITICAL9.6DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable...
CVE-2025-66470MEDIUM6.1NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.inter...
CVE-2025-14285CRITICAL9.8A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now