2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5103MEDIUM4.9The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'defau...
CVE-2025-4420MEDIUM6.4The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-1725MEDIUM6.4The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner...
CVE-2025-46355HIGH7.3Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY...
CVE-2025-41428MEDIUM6.9Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. I...
CVE-2025-21479HIGH8.6Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-4567MEDIUM4.8The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate ...
CVE-2025-3662MEDIUM6.1The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to popul...
CVE-2025-3584MEDIUM4.8The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which coul...
CVE-2025-31712MEDIUM6.2In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial...
CVE-2025-31711MEDIUM6.2In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of s...
CVE-2025-31710HIGH8.4In engineermode service, there is a possible command injection due to improper input validation. This could lead to loca...
CVE-2025-27038HIGH7.5Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVE-2025-27031HIGH7.8memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
CVE-2025-27029HIGH7.5Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
CVE-2025-21486HIGH7.8Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
CVE-2025-21485HIGH7.8Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
CVE-2025-21480HIGH8.6Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21463HIGH7.5Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2025-4797CRITICAL9.8The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo...
CVE-2025-4224HIGH7.2The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upl...
CVE-2025-4047MEDIUM4.3The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check...
CVE-2025-2939MEDIUM5.6The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
CVE-2025-5419HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl...
CVE-2025-5068HIGH8.8Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now