2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5103 | MEDIUM | 4.9 | 0.3% | Jun 3, 2025 | The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'defau... |
| CVE-2025-4420 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-1725 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner... |
| CVE-2025-46355 | HIGH | 7.3 | 0.1% | Jun 3, 2025 | Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY... |
| CVE-2025-41428 | MEDIUM | 6.9 | 0.6% | Jun 3, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. I... |
| CVE-2025-21479 | HIGH | 8.6 | 0.7% | Jun 3, 2025 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. |
| CVE-2025-4567 | MEDIUM | 4.8 | 0.2% | Jun 3, 2025 | The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate ... |
| CVE-2025-3662 | MEDIUM | 6.1 | 0.2% | Jun 3, 2025 | The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to popul... |
| CVE-2025-3584 | MEDIUM | 4.8 | 0.2% | Jun 3, 2025 | The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which coul... |
| CVE-2025-31712 | MEDIUM | 6.2 | 0.1% | Jun 3, 2025 | In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial... |
| CVE-2025-31711 | MEDIUM | 6.2 | 0.1% | Jun 3, 2025 | In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of s... |
| CVE-2025-31710 | HIGH | 8.4 | 0.4% | Jun 3, 2025 | In engineermode service, there is a possible command injection due to improper input validation. This could lead to loca... |
| CVE-2025-27038 | HIGH | 7.5 | 0.8% | Jun 3, 2025 | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. |
| CVE-2025-27031 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed. |
| CVE-2025-27029 | HIGH | 7.5 | 0.2% | Jun 3, 2025 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. |
| CVE-2025-21486 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. |
| CVE-2025-21485 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. |
| CVE-2025-21480 | HIGH | 8.6 | 0.4% | Jun 3, 2025 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. |
| CVE-2025-21463 | HIGH | 7.5 | 0.2% | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. |
| CVE-2025-4797 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo... |
| CVE-2025-4224 | HIGH | 7.2 | 0.2% | Jun 3, 2025 | The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upl... |
| CVE-2025-4047 | MEDIUM | 4.3 | 0.2% | Jun 3, 2025 | The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check... |
| CVE-2025-2939 | MEDIUM | 5.6 | 0.5% | Jun 3, 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up... |
| CVE-2025-5419 | HIGH | 8.8 | 6.5% | Jun 3, 2025 | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl... |
| CVE-2025-5068 | HIGH | 8.8 | 2.6% | Jun 3, 2025 | Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now