2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64868MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64866MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64854MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64838MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64830MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64618MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64610MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64589MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64588MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64584MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2025-64542MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2025-52657LOW3.5HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the...
CVE-2025-52652LOW3.5HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content,...
CVE-2025-52651LOW3.5HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause u...
CVE-2025-9049HIGH8.8The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2025-15647MEDIUM5.5CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge in...
CVE-2025-15614LOW3.3ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z arc...
CVE-2025-15694LOW3.5The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before output...
CVE-2025-15693LOW2.7The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its admini...
CVE-2025-14945MEDIUM5.4The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-67066CRITICAL9.8SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtyp...
CVE-2025-15691MEDIUM5.3The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before cre...
CVE-2025-12737HIGH8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This ov...
CVE-2025-9314CRITICAL9.8The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in th...
CVE-2025-8945MEDIUM5.3The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now