2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0672LOW3.8An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user...
CVE-2025-0209MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due...
CVE-2025-9900HIGH8.8A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes ...
CVE-2025-56304MEDIUM6.1Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
CVE-2025-0663MEDIUM6.8A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada...
CVE-2025-5717HIGH7.2An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input valida...
CVE-2025-57407MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticat...
CVE-2025-4760MEDIUM4.8An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper valida...
CVE-2025-9844HIGH8.8Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable...
CVE-2025-8354HIGH7.8A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A maliciou...
CVE-2025-6921HIGH7.5The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (R...
CVE-2025-9846CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry In...
CVE-2025-10184HIGH8.2The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provi...
CVE-2025-9966HIGH7.3Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service ...
CVE-2025-9965CRITICAL9.3Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any ap...
CVE-2025-9964HIGH8.6No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. T...
CVE-2025-9963CRITICAL9.4A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with r...
CVE-2025-10244HIGH8.7A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross...
CVE-2025-9962CRITICAL10A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authenticatio...
CVE-2025-9342MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privile...
CVE-2025-7106MEDIUM5.3danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c...
CVE-2025-10412CRITICAL9.8The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl...
CVE-2025-9798HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft...
CVE-2025-10857CRITICAL9.8A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown fu...
CVE-2025-10147CRITICAL9.8The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now