2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11051MEDIUM6.5A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow...
CVE-2025-9816HIGH7.2The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-3193HIGH7.5Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in t...
CVE-2025-11050HIGH8.8A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E...
CVE-2025-10954HIGH7.5Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic ...
CVE-2025-11049HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of ...
CVE-2025-10499MEDIUM4.3The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-10498MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-8440MEDIUM6.4The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in...
CVE-2025-36239MEDIUM6.1IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u...
CVE-2025-59945HIGH8.1SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated ...
CVE-2025-59939HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks...
CVE-2025-59938MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from ...
CVE-2025-59936CRITICAL9.4get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache ...
CVE-2025-59932HIGH8.2Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previo...
CVE-2025-36144MEDIUM5.5IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use...
CVE-2025-59934CRITICAL9.4Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verifica...
CVE-2025-59845HIGH8.2Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Pr...
CVE-2025-11048HIGH8.8A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno...
CVE-2025-11047HIGH8.8A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap...
CVE-2025-11046CRITICAL9.8A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /...
CVE-2025-11045HIGH7.3A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function ...
CVE-2025-10657HIGH8.7In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/ha...
CVE-2025-57692MEDIUM6.8PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e...
CVE-2025-50879Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now