2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47870MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team in...
CVE-2025-47700LOW3.5Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows...
CVE-2025-36530MEDIUM4.9Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate fi...
CVE-2025-8607MEDIUM6.4The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-8592HIGH8.1The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2....
CVE-2025-7390CRITICAL9.1A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is conf...
CVE-2025-7221MEDIUM4.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-53505MEDIUM5.3Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabil...
CVE-2025-53504MEDIUM5.4Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vuln...
CVE-2025-57832Rejected reason: Not used
CVE-2025-57831Rejected reason: Not used
CVE-2025-57830Rejected reason: Not used
CVE-2025-57829Rejected reason: Not used
CVE-2025-57828Rejected reason: Not used
CVE-2025-57827Rejected reason: Not used
CVE-2025-57826Rejected reason: Not used
CVE-2025-57825Rejected reason: Not used
CVE-2025-57824Rejected reason: Not used
CVE-2025-48355MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource ...
CVE-2025-48978HIGH7.5An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a mal...
CVE-2025-43300CRITICAL10An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1...
CVE-2025-27217CRITICAL9.1A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to mak...
CVE-2025-27216HIGH8.8Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with cert...
CVE-2025-27215HIGH8.1An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast ...
CVE-2025-27214CRITICAL9.8A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now