2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15678 | MEDIUM | 6.1 | 0.2% | Aug 6, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use... |
| CVE-2025-63823 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote ... |
| CVE-2025-63822 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate... |
| CVE-2025-70962 | HIGH | 7.5 | — | Aug 5, 2026 | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ... |
| CVE-2025-15677 | LOW | 3.5 | 0.2% | Aug 5, 2026 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin... |
| CVE-2025-29296 | CRITICAL | 9.8 | — | Aug 4, 2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V... |
| CVE-2025-15631 | MEDIUM | 5.9 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al... |
| CVE-2025-15630 | MEDIUM | 5.9 | 0.2% | Aug 3, 2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t... |
| CVE-2025-15629 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati... |
| CVE-2025-15628 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr... |
| CVE-2025-15627 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to... |
| CVE-2025-15544 | MEDIUM | 5.9 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc... |
| CVE-2025-9291 | MEDIUM | 6.5 | 0.2% | Aug 3, 2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif... |
| CVE-2025-15673 | MEDIUM | 4.9 | 0.2% | Aug 3, 2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an... |
| CVE-2025-15672 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa... |
| CVE-2025-71401 | CRITICAL | 9.3 | 0.3% | Aug 2, 2026 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B... |
| CVE-2025-71400 | HIGH | 7.1 | 0.2% | Aug 2, 2026 | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet... |
| CVE-2025-71399 | HIGH | 8.8 | 0.3% | Aug 2, 2026 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize... |
| CVE-2025-15675 | MEDIUM | 4.8 | 0.2% | Aug 2, 2026 | The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor... |
| CVE-2025-71404 | MEDIUM | 5.1 | 0.4% | Aug 1, 2026 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ... |
| CVE-2025-71403 | HIGH | 7.1 | 0.2% | Aug 1, 2026 | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ... |
| CVE-2025-71402 | LOW | 2 | 0.2% | Aug 1, 2026 | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou... |
| CVE-2025-14073 | MEDIUM | 5.3 | 0.2% | Aug 1, 2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur... |
| CVE-2025-14469 | MEDIUM | 4.3 | 0.1% | Aug 1, 2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-15669 | MEDIUM | 4.8 | 0.2% | Aug 1, 2026 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now