2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11962HIGH7.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive ...
CVE-2025-64406MEDIUM4.3An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash t...
CVE-2025-64405HIGH7.5Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-64404HIGH7.5Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice...
CVE-2025-64403HIGH8.1Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A...
CVE-2025-64402MEDIUM6.5Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-64401HIGH7.5Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-12903HIGH7.5The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missin...
CVE-2025-12732MEDIUM4.3The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sen...
CVE-2025-13047Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-13046Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12872MEDIUM5.4The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote ...
CVE-2025-12871CRITICAL9.8The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to c...
CVE-2025-12870CRITICAL9.8The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to s...
CVE-2025-12869MEDIUM4.8The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administr...
CVE-2025-12633HIGH7.5The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-12113MEDIUM4.3The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unaut...
CVE-2025-12018MEDIUM4.4The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2025-11560HIGH7.1The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it ba...
CVE-2025-12901MEDIUM4.3The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-12833MEDIUM4.3The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2025-12087MEDIUM4.3The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i...
CVE-2025-54983MEDIUM5.2A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under sp...
CVE-2025-40111HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix Use-after-free in validation Nodes...
CVE-2025-40110In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a null-ptr access in the cursor sno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now