2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15678MEDIUM6.1The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use...
CVE-2025-63823CRITICAL9.8My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote ...
CVE-2025-63822HIGH8.1SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate...
CVE-2025-70962HIGH7.5Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ...
CVE-2025-15677LOW3.5The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin...
CVE-2025-29296CRITICAL9.8H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V...
CVE-2025-15631MEDIUM5.9A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al...
CVE-2025-15630MEDIUM5.9A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t...
CVE-2025-15629HIGH7.5A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati...
CVE-2025-15628HIGH7.5Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr...
CVE-2025-15627HIGH7.5A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to...
CVE-2025-15544MEDIUM5.9A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assoc...
CVE-2025-9291MEDIUM6.5A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif...
CVE-2025-15673MEDIUM4.9The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an...
CVE-2025-15672HIGH8.1The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa...
CVE-2025-71401CRITICAL9.3better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B...
CVE-2025-71400HIGH7.1better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet...
CVE-2025-71399HIGH8.8Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize...
CVE-2025-15675MEDIUM4.8The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor...
CVE-2025-71404MEDIUM5.1better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ...
CVE-2025-71403HIGH7.1better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ...
CVE-2025-71402LOW2better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou...
CVE-2025-14073MEDIUM5.3The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur...
CVE-2025-14469MEDIUM4.3The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-15669MEDIUM4.8The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now