2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-1454MEDIUM5.4The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2025-1303MEDIUM6.1The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in...
CVE-2025-1289MEDIUM4.8The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow ...
CVE-2025-1288MEDIUM6.1The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2025-1286MEDIUM6.1The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting...
CVE-2025-1033MEDIUM4.8The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high ...
CVE-2025-0688MEDIUM6.1The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ...
CVE-2025-0687MEDIUM6.1The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ...
CVE-2025-0329MEDIUM4.8The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou...
CVE-2025-4714CRITICAL9.8A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is a...
CVE-2025-4713CRITICAL9.8A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som...
CVE-2025-4712CRITICAL9.8A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit...
CVE-2025-32922HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This iss...
CVE-2025-30476HIGH7.5Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated ...
CVE-2025-30475CRITICAL9.8Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthe...
CVE-2025-26481HIGH7.5Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A ...
CVE-2025-4711CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects a...
CVE-2025-4710CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected ...
CVE-2025-4709CRITICAL9.8A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerabi...
CVE-2025-47774LOW2.9Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, t...
CVE-2025-47285LOW2.9Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `...
CVE-2025-47279LOW3.1Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i...
CVE-2025-44110MEDIUM5.4FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.
CVE-2025-43853MEDIUM5.5The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA...
CVE-2025-4708CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now