2025 CVE Vulnerabilities
45,269 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5735 | HIGH | 8.8 | 0.8% | Jun 6, 2025 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unkno... |
| CVE-2025-5734 | HIGH | 8.8 | 0.8% | Jun 6, 2025 | A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affec... |
| CVE-2025-5732 | HIGH | 8.8 | 0.3% | Jun 6, 2025 | A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. T... |
| CVE-2025-3321 | CRITICAL | 9.4 | 0.2% | Jun 6, 2025 | A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the... |
| CVE-2025-5729 | HIGH | 7.5 | 0.3% | Jun 6, 2025 | A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management Sy... |
| CVE-2025-5728 | HIGH | 8.8 | 0.4% | Jun 6, 2025 | A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulner... |
| CVE-2025-5727 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This af... |
| CVE-2025-5703 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versio... |
| CVE-2025-5699 | MEDIUM | 5.5 | 0.2% | Jun 6, 2025 | The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all vers... |
| CVE-2025-5686 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode... |
| CVE-2025-5586 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-5565 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all... |
| CVE-2025-5563 | MEDIUM | 6.5 | 0.3% | Jun 6, 2025 | The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, a... |
| CVE-2025-5541 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcod... |
| CVE-2025-5538 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' sho... |
| CVE-2025-5536 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortc... |
| CVE-2025-5534 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-5533 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcod... |
| CVE-2025-5486 | CRITICAL | 9.8 | 0.4% | Jun 6, 2025 | The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the W... |
| CVE-2025-5019 | MEDIUM | 5.4 | 0.1% | Jun 6, 2025 | The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable... |
| CVE-2025-5018 | HIGH | 7.1 | 0.3% | Jun 6, 2025 | The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing cap... |
| CVE-2025-4966 | MEDIUM | 6.1 | 0.1% | Jun 6, 2025 | The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-4964 | MEDIUM | 4.9 | 0.3% | Jun 6, 2025 | The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter ... |
| CVE-2025-48911 | HIGH | 8.2 | 0.1% | Jun 6, 2025 | Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulne... |
| CVE-2025-48910 | MEDIUM | 5.5 | 0.1% | Jun 6, 2025 | Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect avail... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now