2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-24771HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content ...
CVE-2025-23970CRITICAL9.8Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation....
CVE-2025-7060HIGH8.1A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part ...
CVE-2025-38176HIGH7.8In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode(...
CVE-2025-38175HIGH7.8In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Comm...
CVE-2025-38174MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration ...
CVE-2025-5920HIGH7.5The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secr...
CVE-2025-5351MEDIUM6.5A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for co...
CVE-2025-53569MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Lib...
CVE-2025-53568MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station allows Cross Site Request Forg...
CVE-2025-53566MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit...
CVE-2025-30983MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip...
CVE-2025-30979HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelatin...
CVE-2025-30969HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Im...
CVE-2025-30947HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade...
CVE-2025-30943MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Pos...
CVE-2025-30929MEDIUM5.3Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control...
CVE-2025-29012MEDIUM5.3Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorre...
CVE-2025-29007MEDIUM4.3Missing Authorization vulnerability in LMSACE LMSACE Connect lmsace-connect allows Exploiting Incorrectly Configured Acc...
CVE-2025-29001MEDIUM4.3Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Acc...
CVE-2025-28971MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer E...
CVE-2025-28969HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widg...
CVE-2025-28967HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Conta...
CVE-2025-28963MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Req...
CVE-2025-28957MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now