2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10700MEDIUM4.3The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-62580HIGH7.8ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2025-62579HIGH7.8ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2025-11683MEDIUM6.5YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential info...
CVE-2025-62375MEDIUM6.9go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness ...
CVE-2025-43313MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, ...
CVE-2025-43282MEDIUM5.5A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPad...
CVE-2025-43281HIGH7.8The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be...
CVE-2025-43280MEDIUM4.7The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an emai...
CVE-2025-11619HIGH8.8Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers ...
CVE-2025-11568MEDIUM4.4A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption for...
CVE-2025-11832CRITICAL9.8Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech...
CVE-2025-62410CRITICAL9.4In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating unt...
CVE-2025-62382HIGH7.7Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate'...
CVE-2025-62381HIGH8.3sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to ...
CVE-2025-62371HIGH7.4OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSe...
CVE-2025-62380LOW2.9mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr...
CVE-2025-62378MEDIUM6.1CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a log...
CVE-2025-58133HIGH7.5Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a dis...
CVE-2025-58132MEDIUM6.5Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of informatio...
CVE-2025-54271MEDIUM5.6Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Conditio...
CVE-2025-20360MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,...
CVE-2025-20359MEDIUM6.5Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,...
CVE-2025-20351MEDIUM6.1A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon...
CVE-2025-20350HIGH7.5A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now