2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-25214HIGH7.5A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev mast...
CVE-2025-8114MEDIUM4.7A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key e...
CVE-2025-51089MEDIUM6.5Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of th...
CVE-2025-51088MEDIUM5.3Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argu...
CVE-2025-51087HIGH8.6Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of...
CVE-2025-51085MEDIUM5.3Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the arg...
CVE-2025-51082MEDIUM5.3Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of...
CVE-2025-36005MEDIUM6.5IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ...
CVE-2025-33109HIGH8.8IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check....
CVE-2025-33013MEDIUM5.5IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ...
CVE-2025-4784CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella ...
CVE-2025-45731MEDIUM6.5A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is delet...
CVE-2025-5243CRITICAL10Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS ...
CVE-2025-4822CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar En...
CVE-2025-40680MEDIUM6.9Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and ...
CVE-2025-8071MEDIUM6.4Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all version...
CVE-2025-7966MEDIUM6.4The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and ...
CVE-2025-7959MEDIUM6.4The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter...
CVE-2025-7835MEDIUM4.3The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-7822MEDIUM4.3The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-7780MEDIUM6.5The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-7695HIGH8.8The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks...
CVE-2025-7690MEDIUM6.1The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-7640HIGH8.1The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-6588MEDIUM6.1The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now