2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53858MEDIUM5.4ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed ...
CVE-2025-41410MEDIUM5.4Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Sl...
CVE-2025-10545MEDIUM4.3Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c...
CVE-2025-0277MEDIUM6.1HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP)...
CVE-2025-0276MEDIUM6.1HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Conte...
CVE-2025-55091MEDIUM6.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-41443MEDIUM4.3Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessin...
CVE-2025-41021MEDIUM5.4Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validati...
CVE-2025-41020HIGH7.5Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker t...
CVE-2025-41019CRITICAL9.3SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete...
CVE-2025-41018CRITICAL9.8SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d...
CVE-2025-62585HIGH7.5Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dua...
CVE-2025-62584HIGH7.5Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
CVE-2025-62583CRITICAL9.8Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CVE-2025-55090MEDIUM6.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-55089CRITICAL9.8In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t...
CVE-2025-55084MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_...
CVE-2025-10850CRITICAL9.8The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1....
CVE-2025-10849MEDIUM5.3The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-10742CRITICAL9.8The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin...
CVE-2025-10706HIGH8.8The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che...
CVE-2025-58778HIGH8.6Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the...
CVE-2025-0275MEDIUM4.3HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset ...
CVE-2025-11814MEDIUM6.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to...
CVE-2025-0274MEDIUM4.3HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users ca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now