2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15473MEDIUM4.3The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated us...
CVE-2025-15038MEDIUM6.9An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can ...
CVE-2025-15037MEDIUM6.8An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne...
CVE-2025-59388CRITICAL9.8A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can th...
CVE-2025-62328LOW3.7HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by defa...
CVE-2025-70041CRITICAL9.8An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.
CVE-2025-70024CRITICAL9.8An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk...
CVE-2025-66956CRITICAL9.9Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t...
CVE-2025-70082LOW2.7The administrator password can be changed without knowledge of the current password. When chained with an authentication...
CVE-2025-68623HIGH8.8In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file dur...
CVE-2025-67041HIGH7.2An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse...
CVE-2025-67039CRITICAL9.8An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe...
CVE-2025-67038CRITICAL9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ...
CVE-2025-67037HIGH7.2An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunne...
CVE-2025-67036HIGH7.2An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying th...
CVE-2025-67035HIGH7.2An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS ...
CVE-2025-67034HIGH7.2An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name"...
CVE-2025-12555MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-14513HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ...
CVE-2025-13929HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-13690MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ...
CVE-2025-12704MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9...
CVE-2025-12697MEDIUM4.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-12690HIGH7.8Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGF...
CVE-2025-12576MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now