2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14010MEDIUM5.5A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sen...
CVE-2025-12826MEDIUM4.8The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,...
CVE-2025-12782MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2025-13513MEDIUM6.1The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` param...
CVE-2025-11727HIGH7.2The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is...
CVE-2025-11379MEDIUM5.3The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and ...
CVE-2025-62173HIGH8.6## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API
CVE-2025-66404HIGH8.8MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is ...
CVE-2025-66293HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-65868HIGH7.5XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted b...
CVE-2025-64055CRITICAL9.8An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access admi...
CVE-2025-66489CRITICAL9.8Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker ...
CVE-2025-66453HIGH7.5Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, w...
CVE-2025-66411MEDIUM5.5Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28...
CVE-2025-66406MEDIUM5Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, the...
CVE-2025-65345MEDIUM6.5alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality all...
CVE-2025-65097MEDIUM6.5RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte...
CVE-2025-65096MEDIUM4.3RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte...
CVE-2025-65027HIGH7.6RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte...
CVE-2025-61727MEDIUM6.5An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certifi...
CVE-2025-50361MEDIUM5.1Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db364...
CVE-2025-13086HIGH7.5Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows...
CVE-2025-12385HIGH8.7Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability i...
CVE-2025-66222CRITICAL9.6DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting...
CVE-2025-66220HIGH7.1Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS ce...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now