2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4799HIGH7.2The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the d...
CVE-2025-4798MEDIUM4.9The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1...
CVE-2025-4666MEDIUM6.4The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versi...
CVE-2025-49793Rejected reason: Not used
CVE-2025-49792Rejected reason: Not used
CVE-2025-49791Rejected reason: Not used
CVE-2025-49790Rejected reason: Not used
CVE-2025-49789Rejected reason: Not used
CVE-2025-49788Rejected reason: Not used
CVE-2025-49787Rejected reason: Not used
CVE-2025-49786Rejected reason: Not used
CVE-2025-49785Rejected reason: Not used
CVE-2025-5959HIGH8.8Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside...
CVE-2025-5958HIGH8.8Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap c...
CVE-2025-4275HIGH7.8A vulnerability in the digital signature verification process does not properly validate variable attributes which allow...
CVE-2025-49091HIGH8.2KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme ...
CVE-2025-32717HIGH8.4Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-30675MEDIUM4.7In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or ...
CVE-2025-1055MEDIUM5.6A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege use...
CVE-2025-5985HIGH7.3A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this i...
CVE-2025-5984MEDIUM5.4A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe...
CVE-2025-47849HIGH8.8A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do...
CVE-2025-47713HIGH8.8A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do...
CVE-2025-47117MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47116MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now