2025 CVE Vulnerabilities

45,210 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12004CRITICAL10Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext...
CVE-2025-11949HIGH8.7EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-10916CRITICAL9.1The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-62702MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62701MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62694MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62699MEDIUM6.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla...
CVE-2025-62696MEDIUM6.9Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found...
CVE-2025-62695MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62684Rejected reason: Not used
CVE-2025-62683Rejected reason: Not used
CVE-2025-62682Rejected reason: Not used
CVE-2025-62681Rejected reason: Not used
CVE-2025-62680Rejected reason: Not used
CVE-2025-62679Rejected reason: Not used
CVE-2025-62678Rejected reason: Not used
CVE-2025-62677Rejected reason: Not used
CVE-2025-9133HIGH8.1A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi...
CVE-2025-8078HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US...
CVE-2025-7851CRITICAL9.8An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-7850HIGH7.2A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542CRITICAL9.8An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-6541HIGH8.8An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2025-54764MEDIUM6.2Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i...
CVE-2025-12001MEDIUM6.1Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now