2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6729MEDIUM6.4The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a...
CVE-2025-6586HIGH7.2The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-6238HIGH8The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth imp...
CVE-2025-6041MEDIUM6.1The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-6039MEDIUM6.4The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4w...
CVE-2025-5956HIGH8.1The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authoriz...
CVE-2025-5953HIGH8.8The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization...
CVE-2025-5933MEDIUM4.3The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-5924MEDIUM4.3The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-5567MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-5322HIGH7.2The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2025-53367HIGH8.4DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version ...
CVE-2025-49826HIGH7.5Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, ...
CVE-2025-49005LOW3.7Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3....
CVE-2025-53370MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ...
CVE-2025-53369HIGH8.6Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descri...
CVE-2025-53368MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ...
CVE-2025-52554MEDIUM4.3n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re...
CVE-2025-34089CRITICAL9.3An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope...
CVE-2025-34088HIGH8.8An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php ...
CVE-2025-34087HIGH8.8An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allow...
CVE-2025-34086HIGH8.8Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achi...
CVE-2025-34082CRITICAL9.3A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh...
CVE-2025-34061CRITICAL9.3A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code ...
CVE-2025-45809MEDIUM5.4SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now