2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6054MEDIUM6.1The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-5818MEDIUM5.5The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forg...
CVE-2025-5753MEDIUM6.4The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a...
CVE-2025-8060HIGH8.8A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is t...
CVE-2025-54120CRITICAL9.3PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,...
CVE-2025-54139MEDIUM6.1HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 ...
CVE-2025-43489MEDIUM5.2A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43488MEDIUM4.8A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu...
CVE-2025-43487MEDIUM6.8A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions...
CVE-2025-43486MEDIUM4.8A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior...
CVE-2025-43485MEDIUM4.5A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu...
CVE-2025-43484MEDIUM6.1A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions pr...
CVE-2025-43483MEDIUM5.7A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43022HIGH7.2A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. T...
CVE-2025-43021MEDIUM5.7A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43020MEDIUM6.8A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12....
CVE-2025-8011HIGH8.8Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-8010HIGH8.8Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-7766HIGH8.6Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network d...
CVE-2025-54141HIGH7.5ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and ...
CVE-2025-54140HIGH7.5pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated pat...
CVE-2025-54138HIGH7.5LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2025-54137HIGH7.3HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were dis...
CVE-2025-54072HIGH8.1yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option i...
CVE-2025-53703HIGH8.7DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now