2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4223MEDIUM4.7The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2025-5058CRITICAL9.8The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2025-4603CRITICAL9.1The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi...
CVE-2025-4602HIGH7.5The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u...
CVE-2025-4336CRITICAL9.8The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2025-5055MEDIUM4.4The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-48756CRITICAL9.8In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small...
CVE-2025-48755CRITICAL9.8In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).
CVE-2025-48754HIGH7.5In the memory_pages crate 0.1.0 for Rust, division by zero can occur.
CVE-2025-48753CRITICAL9.8In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.
CVE-2025-48752CRITICAL9.8In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
CVE-2025-48751CRITICAL9.8The process_lock crate 0.1.0 for Rust allows data races in unlock.
CVE-2025-3869MEDIUM6.1The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9....
CVE-2025-5119CRITICAL9.8A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code o...
CVE-2025-48741MEDIUM6.8A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5...
CVE-2025-48740MEDIUM5.9A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 ...
CVE-2025-48739MEDIUM4.6A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0...
CVE-2025-48738MEDIUM6.9An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, an...
CVE-2025-48735MEDIUM4.3A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230...
CVE-2025-46176MEDIUM6.5Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotel...
CVE-2025-44998MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows...
CVE-2025-48378MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-48377MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-48376LOW2.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-48375MEDIUM5.3Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equiva...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now