2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4827HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615....
CVE-2025-4101MEDIUM4.3The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss...
CVE-2025-48187CRITICAL9.8RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against ...
CVE-2025-4669MEDIUM5.4The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcod...
CVE-2025-3888MEDIUM5.4The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versi...
CVE-2025-3527MEDIUM5.4The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2025-4826HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809....
CVE-2025-4825HIGH8.8A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulner...
CVE-2025-4824HIGH8.8A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This a...
CVE-2025-4823HIGH8.8A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Aff...
CVE-2025-4610MEDIUM6.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme...
CVE-2025-4819LOW3.1A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of th...
CVE-2025-4391CRITICAL9.8The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v...
CVE-2025-4389CRITICAL9.8The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to mis...
CVE-2025-4190HIGH7.2The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege us...
CVE-2025-3812HIGH8.1The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-4818CRITICAL9.8A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been rated as critical. This issue a...
CVE-2025-4817CRITICAL9.8A vulnerability was found in Sourcecodester Doctor's Appointment System 1.0. It has been declared as critical. This vuln...
CVE-2025-4816CRITICAL9.8A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This af...
CVE-2025-4194MEDIUM6.1The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-4189MEDIUM6.1The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-4815CRITICAL9.8A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue...
CVE-2025-4814CRITICAL9.8A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this ...
CVE-2025-1706HIGH7.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2025-4813CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Human Metapneumovirus Testing Management Syst...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now