2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4501HIGH7.8A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects ...
CVE-2025-4500HIGH7.8A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected...
CVE-2025-4499HIGH7.8A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by thi...
CVE-2025-3878MEDIUM5.4The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-3876HIGH8.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insuff...
CVE-2025-4498HIGH7.8A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is th...
CVE-2025-2158HIGH8.8The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L...
CVE-2025-4497HIGH7.8A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue af...
CVE-2025-2944MEDIUM6.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button an...
CVE-2025-4496CRITICAL9.8A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It ha...
CVE-2025-47770Rejected reason: Not used
CVE-2025-47769Rejected reason: Not used
CVE-2025-47768Rejected reason: Not used
CVE-2025-47767Rejected reason: Not used
CVE-2025-47766Rejected reason: Not used
CVE-2025-47765Rejected reason: Not used
CVE-2025-47764Rejected reason: Not used
CVE-2025-47763Rejected reason: Not used
CVE-2025-47762Rejected reason: Not used
CVE-2025-1137HIGH8.8IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privil...
CVE-2025-4495MEDIUM5.4A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability i...
CVE-2025-47424HIGH7.1Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, ...
CVE-2025-3794MEDIUM5.4The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2025-4494CRITICAL9.8A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin...
CVE-2025-4492CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Online Food Ordering System 1.0. This iss...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now