2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58294MEDIUM5.5Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-66361MEDIUM6.5An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p...
CVE-2025-66360HIGH8.8An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo...
CVE-2025-66359MEDIUM6.1An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl...
CVE-2025-13338Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3261Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12421CRITICAL9.9Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that t...
CVE-2025-12559MEDIUM4.3Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em...
CVE-2025-13765MEDIUM4.3Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De...
CVE-2025-13758LOW3.5Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, throu...
CVE-2025-13757HIGH8.8SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025...
CVE-2025-12419CRITICAL9.9Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat...
CVE-2025-8890CRITICAL9.3Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman...
CVE-2025-13692HIGH7.2The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2025-12140CRITICAL9.3The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlP...
CVE-2025-12971MEDIUM4.3The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul...
CVE-2025-59454MEDIUM4.3In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour...
CVE-2025-59302MEDIUM4.7In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following ...
CVE-2025-54057MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This ...
CVE-2025-59890HIGH7.3Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths ...
CVE-2025-13742MEDIUM6.1Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used ...
CVE-2025-10476MEDIUM4.3The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-59026MEDIUM5.4Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend...
CVE-2025-59025MEDIUM6.1Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us...
CVE-2025-30190MEDIUM5.4Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now