2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57734MEDIUM6.5In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
CVE-2025-57733LOW3.8In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
CVE-2025-57732MEDIUM6.3In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
CVE-2025-57731MEDIUM5.4In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
CVE-2025-57730MEDIUM4.6In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
CVE-2025-57729HIGH7.3In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
CVE-2025-57728MEDIUM6.5In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
CVE-2025-57727HIGH7.5In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
CVE-2025-9229MEDIUM5.3Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated att...
CVE-2025-9228MEDIUM4.3MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowin...
CVE-2025-5261HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Ex...
CVE-2025-5260HIGH8.6Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Requ...
CVE-2025-9225MEDIUM5.5Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fle...
CVE-2025-55715HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows...
CVE-2025-54750HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54735HIGH8.8Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This i...
CVE-2025-54726CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS A...
CVE-2025-54713CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom...
CVE-2025-54677HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPres...
CVE-2025-54670HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oi...
CVE-2025-54056HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Respo...
CVE-2025-54055HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Druco dru...
CVE-2025-54053MEDIUM6.6Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue...
CVE-2025-54052HIGH7.5Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl...
CVE-2025-54049CRITICAL9.9Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now