2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6720MEDIUM5.3The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th...
CVE-2025-29757CRITICAL9.4An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous at...
CVE-2025-7697CRITICAL9.8The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable...
CVE-2025-7696CRITICAL9.8The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to ...
CVE-2025-7669MEDIUM6.1The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2025-7661MEDIUM6.4The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marti...
CVE-2025-7658MEDIUM6.4The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temph...
CVE-2025-7655MEDIUM6.4The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' s...
CVE-2025-7653MEDIUM6.4The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode...
CVE-2025-52924MEDIUM4In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untruste...
CVE-2025-7396MEDIUM4.6In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding conf...
CVE-2025-7395CRITICAL9.2A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VA...
CVE-2025-7394CRITICAL9.8In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to ...
CVE-2025-27210HIGH7.5An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO...
CVE-2025-27209HIGH7.5The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation r...
CVE-2025-7814CRITICAL9.8A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability af...
CVE-2025-7807HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the functio...
CVE-2025-7806HIGH8.8A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSaf...
CVE-2025-50583MEDIUM4.8StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module...
CVE-2025-50582MEDIUM4.8StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.
CVE-2025-50581MEDIUM4.8MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do...
CVE-2025-7805HIGH8.8A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSett...
CVE-2025-7803MEDIUM5.1A vulnerability was found in descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277. It has been classifie...
CVE-2025-54310MEDIUM5.3qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidge...
CVE-2025-50708HIGH7.5An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token componen...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now