2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64459CRITICAL9.1An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, ...
CVE-2025-64458HIGH7.5An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s...
CVE-2025-61084HIGH7.1MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h...
CVE-2025-52602MEDIUM4.2HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint...
CVE-2025-47151CRITICAL9.8A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39;ouvert Lasso 2.5.1 ...
CVE-2025-46784HIGH7.5A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouver...
CVE-2025-46705HIGH7.5A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2....
CVE-2025-46404HIGH7.5A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert La...
CVE-2025-3125HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp...
CVE-2025-12497HIGH8.1The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version...
CVE-2025-11745MEDIUM6.4The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ...
CVE-2025-58337MEDIUM5.4An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, ...
CVE-2025-12469MEDIUM4.3The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne...
CVE-2025-12468MEDIUM5.3The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne...
CVE-2025-12192MEDIUM5.3The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15....
CVE-2025-11987MEDIUM6.4The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-p...
CVE-2025-11820MEDIUM6.4The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl...
CVE-2025-55108CRITICAL10The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un...
CVE-2025-12677MEDIUM5.3The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12676MEDIUM5.3The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5...
CVE-2025-12675MEDIUM4.3The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2025-12674CRITICAL9.8The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-10622HIGH8A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set...
CVE-2025-64151HIGH8.4Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A ...
CVE-2025-62225HIGH8.4Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now