2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64450Rejected reason: Not used
CVE-2025-64449Rejected reason: Not used
CVE-2025-64448Rejected reason: Not used
CVE-2025-12580MEDIUM6.1The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in ...
CVE-2025-11835MEDIUM5.3The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2025-8871MEDIUM5.6The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...
CVE-2025-12582MEDIUM4.3The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2025-12735CRITICAL9.8The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio...
CVE-2025-64110HIGH7.5Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen...
CVE-2025-64109HIGH8.8Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta all...
CVE-2025-64108HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr...
CVE-2025-64107HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may ...
CVE-2025-64106HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor'...
CVE-2025-62722MEDIUM5.4LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functio...
CVE-2025-59596MEDIUM6.5CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addr...
CVE-2025-59595HIGH7.5CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12....
CVE-2025-62721MEDIUM6.5LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints...
CVE-2025-62720MEDIUM6.5LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to expo...
CVE-2025-62719MEDIUM4.3LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function...
CVE-2025-62715MEDIUM5.4ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Script...
CVE-2025-62520MEDIUM4.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-...
CVE-2025-62507HIGH8.8Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD...
CVE-2025-62369HIGH7.2Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con...
CVE-2025-56230HIGH7.5Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.
CVE-2025-54526HIGH8.4Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted pro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now