2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13782CRITICAL9.8A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is...
CVE-2025-66424MEDIUM6.5Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40...
CVE-2025-66423HIGH7.1Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.1...
CVE-2025-66422MEDIUM4.3Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is ...
CVE-2025-66421MEDIUM5.4Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6....
CVE-2025-66420MEDIUM5.4Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and ...
CVE-2025-13615CRITICAL9.8The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin...
CVE-2025-6666LOW2A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an ...
CVE-2025-66291MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r...
CVE-2025-66290MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm...
CVE-2025-66289HIGH8.8OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not i...
CVE-2025-66225HIGH8.8OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo...
CVE-2025-66224HIGH8.8OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains a...
CVE-2025-65892MEDIUM6.1Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execut...
CVE-2025-65540MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. ...
CVE-2025-66223HIGH8.4OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not exp...
CVE-2025-66221MEDIUM5.3Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows p...
CVE-2025-66217HIGH7.5AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQ...
CVE-2025-66216CRITICAL9.8AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been ident...
CVE-2025-61915MEDIUM6.7OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2....
CVE-2025-58436MEDIUM5.5OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2....
CVE-2025-53939HIGH8.8Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a sh...
CVE-2025-53900HIGH8.8Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of rol...
CVE-2025-53899HIGH7.2Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is ...
CVE-2025-53897MEDIUM6.8Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now