2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11748MEDIUM4.3The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, ...
CVE-2025-12583MEDIUM6.4The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-11452HIGH7.5The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' ...
CVE-2025-64496HIGH8Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and ...
CVE-2025-64495MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 an...
CVE-2025-64494MEDIUM4.6Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places whe...
CVE-2025-64493MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8....
CVE-2025-64492HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0...
CVE-2025-64491MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64490HIGH8.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64489HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64488HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-64486CRITICAL9.3calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary ass...
CVE-2025-64485MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1...
CVE-2025-12911MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-12910MEDIUM6.2Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain pote...
CVE-2025-12909MEDIUM5.3Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cr...
CVE-2025-12908MEDIUM5.4Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a rem...
CVE-2025-12907HIGH8.8Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker...
CVE-2025-12906MEDIUM5.4Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-12905MEDIUM5.4Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker t...
CVE-2025-64437MEDIUM5KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler doe...
CVE-2025-64436MEDIUM5.3KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the vir...
CVE-2025-64435MEDIUM5.3KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controll...
CVE-2025-64434MEDIUM6.3KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification l...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now