2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48161HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMT...
CVE-2025-48156MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wal...
CVE-2025-48155MEDIUM5.3Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all...
CVE-2025-48153HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows St...
CVE-2025-48150MEDIUM4.3Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugi...
CVE-2025-7699HIGH7.1An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to c...
CVE-2025-7035MEDIUM5.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_c...
CVE-2025-6993HIGH8.8The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the...
CVE-2025-5284MEDIUM6.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2025-40985HIGH8.3SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an atta...
CVE-2025-40724MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to exe...
CVE-2025-22227MEDIUM6.1In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to hap...
CVE-2025-7703LOW3.1Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.
CVE-2025-27465MEDIUM4.3Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it...
CVE-2025-7673CRITICAL9.8A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior...
CVE-2025-7359HIGH8.2The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici...
CVE-2025-6747MEDIUM6.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_ma...
CVE-2025-6043HIGH8.1The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F...
CVE-2025-5845MEDIUM6.4The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter i...
CVE-2025-5843MEDIUM6.4The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions...
CVE-2025-52690HIGH8.1Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially ...
CVE-2025-52689CRITICAL9.8Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with a...
CVE-2025-52688CRITICAL9.8Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the acce...
CVE-2025-52687LOW2.4Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point...
CVE-2025-2800MEDIUM6.1The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now