2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71426HIGH7.1Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not...
CVE-2025-71425HIGH7.3Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contr...
CVE-2025-71423HIGH7.3Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initialize...
CVE-2025-51457HIGH8.8D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at ...
CVE-2025-1281HIGH8.8The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-71421HIGH7.2UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint tha...
CVE-2025-61682HIGH8.6Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2025-14754HIGH8.8IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on...
CVE-2025-14753HIGH7.5IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send...
CVE-2025-15697HIGH7.1The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sev...
CVE-2025-59607HIGH7.8Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2025-56565HIGH7.6DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in...
CVE-2025-14871HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and...
CVE-2025-66974HIGH7.5An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attacke...
CVE-2025-15679HIGH7.3Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a pa...
CVE-2025-57231HIGH7.5Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local file...
CVE-2025-9049HIGH8.8The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2025-12737HIGH8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This ov...
CVE-2025-15485HIGH8.2The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowin...
CVE-2025-46418HIGH7.6Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
CVE-2025-12768HIGH8.6A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could e...
CVE-2025-30156HIGH8.9Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2...
CVE-2025-61480HIGH7.5An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ...
CVE-2025-61479HIGH7.5An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ...
CVE-2025-61478HIGH7.5An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now