2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14815CRITICAL9.3Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi...
CVE-2025-1794MEDIUM5.4The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers...
CVE-2025-14732MEDIUM6.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-20628MEDIUM6.9An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w...
CVE-2025-69515CRITICAL9.1An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int...
CVE-2025-56015HIGH7.5In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
CVE-2025-14859HIGH7The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmwa...
CVE-2025-14858MEDIUM5.1The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability...
CVE-2025-14857MEDIUM5.4An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware ...
CVE-2025-71058CRITICAL9.1Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originate...
CVE-2025-70844MEDIUM6.1yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco...
CVE-2025-14944MEDIUM5.3The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2...
CVE-2025-14821HIGH7A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secur...
CVE-2025-52908CRITICAL9.8An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13...
CVE-2025-24819MEDIUM5.7Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter...
CVE-2025-24818HIGH8Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme...
CVE-2025-24817HIGH8Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme...
CVE-2025-62818CRITICAL9.8An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-52909CRITICAL9.8An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13...
CVE-2025-39666HIGH7.3Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Che...
CVE-2025-15611MEDIUM5.4The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function be...
CVE-2025-65116MEDIUM5.5Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati...
CVE-2025-65115CRITICAL9.8Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - O...
CVE-2025-13044MEDIUM6.2IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar...
CVE-2025-54601HIGH7An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 12...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now