2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10736MEDIUM6.5The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-71276MEDIUM6.1SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
CVE-2025-14037HIGH8.1The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi...
CVE-2025-13910MEDIUM6.1The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJA...
CVE-2025-63261HIGH7.8AWStats 8.0 is vulnerable to Command Injection via the open function
CVE-2025-55988HIGH7.2An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire...
CVE-2025-63260MEDIUM5.4SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-U...
CVE-2025-62846MEDIUM6.7An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th...
CVE-2025-62845MEDIUM6.7An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l...
CVE-2025-62844MEDIUM5.5A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c...
CVE-2025-62843MEDIUM6.8An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. ...
CVE-2025-59383CRITICAL9.1A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi...
CVE-2025-15608CRITICAL9.8This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe ...
CVE-2025-15607CRITICAL9.8A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo...
CVE-2025-67260HIGH8.8The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln...
CVE-2025-46597HIGH7.5Bitcoin Core 0.13.0 through 29.x has an integer overflow.
CVE-2025-46598MEDIUM5.3Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
CVE-2025-67115MEDIUM6.5A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor...
CVE-2025-67114CRITICAL9.8Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng...
CVE-2025-67113CRITICAL9.8OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be...
CVE-2025-67112CRITICAL9.8Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F...
CVE-2025-69720HIGH7.8The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog...
CVE-2025-71260HIGH8.8BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in ...
CVE-2025-71259HIGH7.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ...
CVE-2025-71258HIGH7.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now