2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15484CRITICAL9.1The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant...
CVE-2025-71282HIGH8.7XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ...
CVE-2025-71281CRITICAL9.8XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in...
CVE-2025-71280MEDIUM5.5XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu...
CVE-2025-71279CRITICAL9.8XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may...
CVE-2025-71278HIGH8.8XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O...
CVE-2025-13855HIGH8.8IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could...
CVE-2025-62184LOW3.4Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf...
CVE-2025-14213HIGH8.3Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack...
CVE-2025-15618CRITICAL9.1Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online...
CVE-2025-41357MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41356MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41355MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t...
CVE-2025-10559CRITICAL9.1A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE...
CVE-2025-10553MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag...
CVE-2025-10551MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat...
CVE-2025-32957HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ...
CVE-2025-66215MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-66038MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com...
CVE-2025-66037MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p...
CVE-2025-49010MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-3716MEDIUM5.3User enumeration in ESET Protect (on-prem) via Response Timing.
CVE-2025-15379CRITICAL10A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_...
CVE-2025-15036CRITICAL10A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif...
CVE-2025-7741LOW2.1Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now