2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53233HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RylanH Storyform s...
CVE-2025-53231HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy T...
CVE-2025-53228HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress S...
CVE-2025-53217HIGH7.6Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Conf...
CVE-2025-52744HIGH7.7Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-tea...
CVE-2025-52603LOW3.5HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow ...
CVE-2025-14547LOW2.3An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs...
CVE-2025-14055LOW2.4An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special...
CVE-2025-10970CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc...
CVE-2025-59819MEDIUM6.5This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an int...
CVE-2025-30416CRITICAL10Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cy...
CVE-2025-30412CRITICAL10Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ...
CVE-2025-30411CRITICAL10Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ...
CVE-2025-30410CRITICAL9.8Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C...
CVE-2025-9208MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W...
CVE-2025-8055MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerabi...
CVE-2025-8054HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows ...
CVE-2025-13672MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W...
CVE-2025-13671MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forger...
CVE-2025-67305CRITICAL9.8In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These ...
CVE-2025-67304CRITICAL9.8In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL ...
CVE-2025-69725MEDIUM4.7An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect vi...
CVE-2025-69674MEDIUM6.4Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute ar...
CVE-2025-71250Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71249Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now