2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6729 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a... |
| CVE-2025-6586 | HIGH | 7.2 | 1.1% | Jul 4, 2025 | The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-6238 | HIGH | 8 | 0.3% | Jul 4, 2025 | The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth imp... |
| CVE-2025-6041 | MEDIUM | 6.1 | 0.1% | Jul 4, 2025 | The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-6039 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4w... |
| CVE-2025-5956 | HIGH | 8.1 | 0.3% | Jul 4, 2025 | The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authoriz... |
| CVE-2025-5953 | HIGH | 8.8 | 0.4% | Jul 4, 2025 | The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization... |
| CVE-2025-5933 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-5924 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-5567 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-5322 | HIGH | 7.2 | 0.6% | Jul 3, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2025-53367 | HIGH | 8.4 | 0.7% | Jul 3, 2025 | DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version ... |
| CVE-2025-49826 | HIGH | 7.5 | 0.8% | Jul 3, 2025 | Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, ... |
| CVE-2025-49005 | LOW | 3.7 | 0.4% | Jul 3, 2025 | Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.... |
| CVE-2025-53370 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ... |
| CVE-2025-53369 | HIGH | 8.6 | 0.3% | Jul 3, 2025 | Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descri... |
| CVE-2025-53368 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ... |
| CVE-2025-52554 | MEDIUM | 4.3 | 0.3% | Jul 3, 2025 | n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re... |
| CVE-2025-34089 | CRITICAL | 9.3 | 1.4% | Jul 3, 2025 | An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope... |
| CVE-2025-34088 | HIGH | 8.8 | 5.1% | Jul 3, 2025 | An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php ... |
| CVE-2025-34087 | HIGH | 8.8 | 5.0% | Jul 3, 2025 | An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allow... |
| CVE-2025-34086 | HIGH | 8.8 | 2.1% | Jul 3, 2025 | Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achi... |
| CVE-2025-34082 | CRITICAL | 9.3 | 5.3% | Jul 3, 2025 | A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh... |
| CVE-2025-34061 | CRITICAL | 9.3 | 1.2% | Jul 3, 2025 | A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code ... |
| CVE-2025-45809 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now