2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10707HIGH8.8A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessage...
CVE-2025-10468HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus ...
CVE-2025-8531MEDIUM6.8Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03...
CVE-2025-10719MEDIUM5.3Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers wit...
CVE-2025-10630MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to ...
CVE-2025-9906HIGH7.3The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c...
CVE-2025-9905HIGH7.3The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c...
CVE-2025-10647HIGH8.8The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2025-7702MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry ...
CVE-2025-7403MEDIUM6.5Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes a...
CVE-2025-5948CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-10458HIGH7.6Parameters are not validated or sanitized, and are later used in various internal operations.
CVE-2025-10457HIGH8.1The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, w...
CVE-2025-10456MEDIUM6.5A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specif...
CVE-2025-5955HIGH8.1The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc...
CVE-2025-10146MEDIUM6.1The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter i...
CVE-2025-8487MEDIUM5.4The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi...
CVE-2025-59717CRITICAL9.8In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .i...
CVE-2025-7937HIGH7.2There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can upda...
CVE-2025-59715MEDIUM5.4SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.
CVE-2025-59714MEDIUM4.9In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
CVE-2025-59713HIGH8.1Snipe-IT before 8.1.18 allows unsafe deserialization.
CVE-2025-59712MEDIUM5.4Snipe-IT before 8.1.18 allows XSS.
CVE-2025-59678Rejected reason: Not used
CVE-2025-59677Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now