2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32736 | MEDIUM | 4.9 | — | Aug 10, 2026 | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all... |
| CVE-2025-71413 | MEDIUM | 5.3 | — | Aug 7, 2026 | Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w... |
| CVE-2025-71411 | MEDIUM | 5.3 | — | Aug 7, 2026 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c... |
| CVE-2025-71410 | MEDIUM | 5.3 | — | Aug 7, 2026 | Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and... |
| CVE-2025-6508 | MEDIUM | 4.3 | — | Aug 6, 2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b... |
| CVE-2025-12317 | MEDIUM | 5 | — | Aug 6, 2026 | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue... |
| CVE-2025-9266 | MEDIUM | 4.3 | — | Aug 6, 2026 | The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-13909 | MEDIUM | 4.3 | — | Aug 6, 2026 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT... |
| CVE-2025-13394 | MEDIUM | 5.4 | — | Aug 6, 2026 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque... |
| CVE-2025-11850 | MEDIUM | 4.3 | — | Aug 6, 2026 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us... |
| CVE-2025-15678 | MEDIUM | 6.1 | — | Aug 6, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use... |
| CVE-2025-15631 | MEDIUM | 5.9 | — | Aug 3, 2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al... |
| CVE-2025-15630 | MEDIUM | 5.9 | — | Aug 3, 2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t... |
| CVE-2025-15544 | MEDIUM | 5.9 | — | Aug 3, 2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc... |
| CVE-2025-9291 | MEDIUM | 6.5 | — | Aug 3, 2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif... |
| CVE-2025-15673 | MEDIUM | 4.9 | — | Aug 3, 2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an... |
| CVE-2025-71401 | MEDIUM | 5.9 | — | Aug 2, 2026 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B... |
| CVE-2025-15675 | MEDIUM | 4.8 | — | Aug 2, 2026 | The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor... |
| CVE-2025-71404 | MEDIUM | 5.1 | — | Aug 1, 2026 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ... |
| CVE-2025-14073 | MEDIUM | 5.3 | — | Aug 1, 2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur... |
| CVE-2025-14469 | MEDIUM | 4.3 | — | Aug 1, 2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-15669 | MEDIUM | 4.8 | — | Aug 1, 2026 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren... |
| CVE-2025-62347 | MEDIUM | 4.3 | — | Jul 31, 2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and... |
| CVE-2025-67651 | MEDIUM | 6.9 | — | Jul 31, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ... |
| CVE-2025-65342 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now