2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9849MEDIUM6.4The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_...
CVE-2025-7368MEDIUM5.3The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information ...
CVE-2025-7366HIGH7.3The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrar...
CVE-2025-6067MEDIUM6.4The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-58439CRITICAL9.1ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, l...
CVE-2025-58375HIGH8.1Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecur...
CVE-2025-58373MEDIUM6.5Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul...
CVE-2025-58372CRITICAL9.8Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul...
CVE-2025-58371CRITICAL9.8Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github w...
CVE-2025-58370HIGH8.1Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerab...
CVE-2025-58369MEDIUM5.3fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, a...
CVE-2025-58367CRITICAL10DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnera...
CVE-2025-58366CRITICAL9.4Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials ...
CVE-2025-57807CRITICAL9.8ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lowe...
CVE-2025-10027MEDIUM6.1A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown func...
CVE-2025-53791MEDIUM4.7Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ...
CVE-2025-10061MEDIUM6.5An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability ...
CVE-2025-10060HIGH7.5MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially...
CVE-2025-10059MEDIUM6.5An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when ...
CVE-2025-9566HIGH8.1There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube ...
CVE-2025-10044MEDIUM4.3A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description ...
CVE-2025-10043Rejected reason: Considered by the maintainers a bug scenario experienced rather than a vulnerability.
CVE-2025-10026MEDIUM6.1A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown fun...
CVE-2025-10025CRITICAL9.8A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file...
CVE-2025-9057MEDIUM6.4The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now