2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71214HIGH7.8An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac...
CVE-2025-71213HIGH7.8An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ...
CVE-2025-71212HIGH7.8A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileg...
CVE-2025-71211CRITICAL9.8A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an...
CVE-2025-71210CRITICAL9.8A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an...
CVE-2025-13479HIGH7.5Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu ...
CVE-2025-13477HIGH7.1Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in...
CVE-2025-32750HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2025-11954HIGH8Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S...
CVE-2025-31985MEDIUM6.5HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-31973CRITICAL9.8HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd...
CVE-2025-33255CRITICAL9.8NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial...
CVE-2025-15369MEDIUM5.3The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due...
CVE-2025-15645MEDIUM5.1Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t...
CVE-2025-57798MEDIUM5.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1...
CVE-2025-61081——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-70950HIGH7.3An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
CVE-2025-51427HIGH7.3An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t...
CVE-2025-40904MEDIUM5.4A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an...
CVE-2025-40903MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid...
CVE-2025-40902MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p...
CVE-2025-40901MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation...
CVE-2025-40900MEDIUM5.1An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-14575LOW1.8An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (...
CVE-2025-15609HIGH7.5The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now