2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15624HIGH7.5Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID...
CVE-2025-15623HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau...
CVE-2025-15622MEDIUM6.2Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals ...
CVE-2025-54502HIGH7.5Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker...
CVE-2025-54510MEDIUM5.9A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with admi...
CVE-2025-43937MEDIUM6.6Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerab...
CVE-2025-43935MEDIUM4.4Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A hi...
CVE-2025-43883MEDIUM4.1Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln...
CVE-2025-36579MEDIUM5.1Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph...
CVE-2025-15621MEDIUM6Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re...
CVE-2025-12624MEDIUM5.4Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail...
CVE-2025-6024MEDIUM6.1The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script...
CVE-2025-14868HIGH8.8The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr...
CVE-2025-13364MEDIUM6.4The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2025-41118CRITICAL9.1Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten...
CVE-2025-63029HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar...
CVE-2025-15636MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You...
CVE-2025-15635MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro...
CVE-2025-15610CRITICAL9.3The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi...
CVE-2025-67841HIGH7.5Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
CVE-2025-53444MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i...
CVE-2025-12141MEDIUM6.5In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif...
CVE-2025-14813HIGH7.5: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a...
CVE-2025-52641MEDIUM5.3HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str...
CVE-2025-40899HIGH8.9A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now