2025 CVE Vulnerabilities

45,269 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5735HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unkno...
CVE-2025-5734HIGH8.8A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affec...
CVE-2025-5732HIGH8.8A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. T...
CVE-2025-3321CRITICAL9.4A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the...
CVE-2025-5729HIGH7.5A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management Sy...
CVE-2025-5728HIGH8.8A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulner...
CVE-2025-5727MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This af...
CVE-2025-5703MEDIUM5.4The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versio...
CVE-2025-5699MEDIUM5.5The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all vers...
CVE-2025-5686MEDIUM6.4The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode...
CVE-2025-5586MEDIUM6.4The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-5565MEDIUM6.4The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all...
CVE-2025-5563MEDIUM6.5The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, a...
CVE-2025-5541MEDIUM6.4The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcod...
CVE-2025-5538MEDIUM6.4The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' sho...
CVE-2025-5536MEDIUM6.4The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortc...
CVE-2025-5534MEDIUM6.4The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-5533MEDIUM6.4The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcod...
CVE-2025-5486CRITICAL9.8The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the W...
CVE-2025-5019MEDIUM5.4The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable...
CVE-2025-5018HIGH7.1The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing cap...
CVE-2025-4966MEDIUM6.1The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-4964MEDIUM4.9The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter ...
CVE-2025-48911HIGH8.2Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulne...
CVE-2025-48910MEDIUM5.5Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect avail...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now