2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58277MEDIUM5.5Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect...
CVE-2025-9560MEDIUM6.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_news...
CVE-2025-11380MEDIUM5.9The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u...
CVE-2025-54654MEDIUM5.5Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service...
CVE-2025-31718HIGH7.5In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of pri...
CVE-2025-31717HIGH7.5In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2025-11590HIGH8.8A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown func...
CVE-2025-9554MEDIUM5.3Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.
CVE-2025-9553MEDIUM5.3Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.
CVE-2025-9552MEDIUM5.3Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With...
CVE-2025-9551MEDIUM6.5Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.Thi...
CVE-2025-9550MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo...
CVE-2025-9549MEDIUM6.5Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 befo...
CVE-2025-8093HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati...
CVE-2025-62162HIGH7.5cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0....
CVE-2025-62159HIGH8.7External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2025-52885MEDIUM6.1Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulne...
CVE-2025-52647MEDIUM6.1The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Head...
CVE-2025-11626MEDIUM5.5MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
CVE-2025-61912MEDIUM5.3python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn...
CVE-2025-61911MEDIUM6.5python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the san...
CVE-2025-11589HIGH8.8A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ...
CVE-2025-11588HIGH8.8A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /cus...
CVE-2025-11586CRITICAL9.8A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgr...
CVE-2025-11585CRITICAL9.8A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now