2025 CVE Vulnerabilities

45,185 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12712MEDIUM6.4The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up...
CVE-2025-12670MEDIUM6.4The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic...
CVE-2025-12666MEDIUM6.4The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin...
CVE-2025-12649MEDIUM6.4The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt...
CVE-2025-12579MEDIUM5.3The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-12578MEDIUM4.3The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-0658HIGH8.7A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev...
CVE-2025-0657HIGH8.8A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed...
CVE-2025-66040LOW3.6Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vuln...
CVE-2025-66035HIGH7.7Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2025-66031HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R...
CVE-2025-66030MEDIUM5.3Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl...
CVE-2025-64344HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64335HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64334HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64333HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64332HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64331HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64330HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-62593HIGH8.8Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited...
CVE-2025-40934CRITICAL9.3XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can ...
CVE-2025-65202HIGH8TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, explo...
CVE-2025-7449MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18...
CVE-2025-6195MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6...
CVE-2025-65670MEDIUM4.3An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now