2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15692LOW3.5The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting ...
CVE-2025-15490MEDIUM5.3The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users t...
CVE-2025-15489MEDIUM5.3The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated u...
CVE-2025-15485HIGH8.2The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowin...
CVE-2025-15481MEDIUM5.3The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all ...
CVE-2025-13398——Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the sam...
CVE-2025-7963MEDIUM6.4The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywavefor...
CVE-2025-15664MEDIUM6.8The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's b...
CVE-2025-15663MEDIUM6.8The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's a...
CVE-2025-46418HIGH7.6Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
CVE-2025-12768HIGH8.6A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could e...
CVE-2025-15613MEDIUM6.5Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attack...
CVE-2025-63607MEDIUM6.1TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter v...
CVE-2025-64649MEDIUM5.9IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te...
CVE-2025-36290MEDIUM5.9IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid...
CVE-2025-36271MEDIUM5.9IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a...
CVE-2025-30156HIGH8.9Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2...
CVE-2025-62343LOW3.1HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sess...
CVE-2025-62342MEDIUM6.4HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of...
CVE-2025-62341LOW3.7HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo...
CVE-2025-61480HIGH7.5An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ...
CVE-2025-61479HIGH7.5An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ...
CVE-2025-61478HIGH7.5An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ...
CVE-2025-51679CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected ...
CVE-2025-51675HIGH7.5An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now