2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13968MEDIUM6.4The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod...
CVE-2025-30008MEDIUM5.4HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users...
CVE-2025-30007HIGH8.8HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat...
CVE-2025-70796HIGH7.5An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc....
CVE-2025-12127Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-11977MEDIUM6.6The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo...
CVE-2025-45422HIGH8.1Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak...
CVE-2025-63579HIGH7.5Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu...
CVE-2025-58151CRITICAL9.4varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ...
CVE-2025-58146CRITICAL9.4There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica...
CVE-2025-27464CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27463CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27462CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-12506MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and ...
CVE-2025-3110HIGH7.5OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at...
CVE-2025-14785MEDIUM6.4The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...
CVE-2025-12799MEDIUM6.5A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config...
CVE-2025-59617HIGH7.3Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2025-59616HIGH7.8Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea...
CVE-2025-59615HIGH7.8Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe...
CVE-2025-53831HIGH8.2DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application o...
CVE-2025-53830CRITICAL9.1Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud...
CVE-2025-53829HIGH8ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack...
CVE-2025-53828HIGH8.5SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli...
CVE-2025-53827CRITICAL9.1ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now