2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13191CRITICAL9.8A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the fil...
CVE-2025-13190HIGH8.8A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the ...
CVE-2025-12849MEDIUM5.3The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28....
CVE-2025-8994MEDIUM6.5The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugi...
CVE-2025-13189CRITICAL9.8A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena...
CVE-2025-12847MEDIUM4.3The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ...
CVE-2025-12494MEDIUM4.3The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insu...
CVE-2025-65072Rejected reason: Not used
CVE-2025-65071Rejected reason: Not used
CVE-2025-65070Rejected reason: Not used
CVE-2025-65069Rejected reason: Not used
CVE-2025-65068Rejected reason: Not used
CVE-2025-65067Rejected reason: Not used
CVE-2025-65066Rejected reason: Not used
CVE-2025-65065Rejected reason: Not used
CVE-2025-65064Rejected reason: Not used
CVE-2025-12182MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize...
CVE-2025-9317HIGH8.4The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f...
CVE-2025-8386HIGH7.2The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper w...
CVE-2025-64309HIGH7.4The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut...
CVE-2025-64308HIGH7.1The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Bri...
CVE-2025-64307HIGH7.1The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized...
CVE-2025-62765HIGH8.7General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a...
CVE-2025-59780HIGH8.7General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all...
CVE-2025-58083CRITICAL10General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could al...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now