2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58276MEDIUM5.5Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability ma...
CVE-2025-48395MEDIUM4.7An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the...
CVE-2025-8944MEDIUM4.3The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of i...
CVE-2025-58400HIGH8.4RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f...
CVE-2025-55671HIGH8.5Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited...
CVE-2025-55037CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI ver...
CVE-2025-41408MEDIUM5.3Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14....
CVE-2025-58401MEDIUM6.8Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacke...
CVE-2025-8684MEDIUM6.4The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions...
CVE-2025-9990HIGH8.1The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
CVE-2025-7445MEDIUM6.5Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
CVE-2025-58362HIGH7.5Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 conta...
CVE-2025-58359MEDIUM6ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 th...
CVE-2025-58352MEDIUM6.5Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex...
CVE-2025-58179MEDIUM6.5Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using A...
CVE-2025-55739MEDIUM5.1api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower t...
CVE-2025-55305MEDIUM6.1Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions belo...
CVE-2025-55244CRITICAL9Azure Bot Service Elevation of Privilege Vulnerability
CVE-2025-55242HIGH7.5Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati...
CVE-2025-55241CRITICAL10Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55238HIGH7.5Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-55209MEDIUM5.1contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versi...
CVE-2025-55190CRITICAL9.9Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 thro...
CVE-2025-54914CRITICAL9.8Azure Networking Elevation of Privilege Vulnerability
CVE-2025-58361CRITICAL9.3Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now