2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15345MEDIUM6.1The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par...
CVE-2025-14870HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-14869HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-13874MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-12669MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an...
CVE-2025-27853HIGH7.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU we...
CVE-2025-27852MEDIUM5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack...
CVE-2025-27851CRITICAL9.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac...
CVE-2025-27850HIGH7.5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics pac...
CVE-2025-32425MEDIUM5.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2025-29338MEDIUM5.6NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff...
CVE-2025-28344HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2025-14767MEDIUM5.5The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2025-14033MEDIUM5.3The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-11159HIGH7.2Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul...
CVE-2025-9989MEDIUM4.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-9988MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat...
CVE-2025-9987MEDIUM5.3The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2025-14755MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct...
CVE-2025-62627HIGH7.2An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ...
CVE-2025-62624HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-62623HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-61972HIGH8.5Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma...
CVE-2025-61971MEDIUM5.9Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now