2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43883MEDIUM4.1Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln...
CVE-2025-36579MEDIUM5.1Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph...
CVE-2025-15621MEDIUM5.7Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re...
CVE-2025-12624MEDIUM5.4Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail...
CVE-2025-6024MEDIUM6.1The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script...
CVE-2025-14868HIGH8.8The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr...
CVE-2025-13364MEDIUM6.4The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2025-41118CRITICAL9.1Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten...
CVE-2025-63029HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar...
CVE-2025-15636MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You...
CVE-2025-15635MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro...
CVE-2025-15610CRITICAL9.3The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi...
CVE-2025-67841HIGH7.5Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
CVE-2025-53444MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i...
CVE-2025-12141MEDIUM6.5In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif...
CVE-2025-14813CRITICAL9.3: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a...
CVE-2025-52641MEDIUM5.3HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str...
CVE-2025-40899HIGH8.9A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat...
CVE-2025-40897HIGH8.1An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric...
CVE-2025-54550HIGH8.1The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xco...
CVE-2025-15470MEDIUM6.5The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th...
CVE-2025-15565MEDIUM5.3The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check...
CVE-2025-70023CRITICAL9.8An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
CVE-2025-68649MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze...
CVE-2025-65136MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now