2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11918HIGH7.3Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the...
CVE-2025-10018MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admi...
CVE-2025-8855HIGH8.1Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio...
CVE-2025-11981MEDIUM4.9The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parame...
CVE-2025-11794MEDIUM4.9Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows sy...
CVE-2025-55073MEDIUM5.3Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between ...
CVE-2025-55070HIGH7.5Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticate...
CVE-2025-41436MEDIUM4.3Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regu...
CVE-2025-11776MEDIUM4.3Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to disc...
CVE-2025-64444HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4...
CVE-2025-10686HIGH7.2The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possib...
CVE-2025-13161HIGH8.7IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo...
CVE-2025-13160MEDIUM6.9IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthe...
CVE-2025-9479MEDIUM4.3Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap ...
CVE-2025-13107MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-13102MEDIUM4.3Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote atta...
CVE-2025-13097MEDIUM5.4Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentiall...
CVE-2025-12904HIGH7.2The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA...
CVE-2025-64530HIGH7.5Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions ...
CVE-2025-64754LOW2.7Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allo...
CVE-2025-64753MEDIUM6.5grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document c...
CVE-2025-64752MEDIUM6.5grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist instal...
CVE-2025-64749MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messa...
CVE-2025-64748MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11...
CVE-2025-64747MEDIUM5.5Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now