2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34068CRITICAL9.3An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5....
CVE-2025-7667HIGH8.1The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-4369MEDIUM5.5The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ ...
CVE-2025-24477MEDIUM6.7A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS...
CVE-2025-7672MEDIUM4.3The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS...
CVE-2025-3621CRITICAL9.6Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho...
CVE-2025-7367MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie...
CVE-2025-7360CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-7341CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-7340CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-5394CRITICAL9.8The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads ...
CVE-2025-5393CRITICAL9.1The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion...
CVE-2025-6265HIGH7.2A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and...
CVE-2025-53891MEDIUM4.3The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found...
CVE-2025-53890CRITICAL9.8pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoa...
CVE-2025-53889MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to...
CVE-2025-53887MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53886MEDIUM4.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53885MEDIUM4.2Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53839MEDIUM4DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interfac...
CVE-2025-53836HIGH8.8XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-53835CRITICAL9XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-53834MEDIUM6.3Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s...
CVE-2025-53833CRITICAL10LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior ...
CVE-2025-53825CRITICAL9.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deplo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now