2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32401CRITICAL9.8An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d...
CVE-2025-32400HIGH7.5An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic...
CVE-2025-32399HIGH7.5An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t...
CVE-2025-32398HIGH7.5A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices ...
CVE-2025-32397HIGH7.5An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic...
CVE-2025-32396HIGH7.5An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic...
CVE-2025-1400LOW3.1Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers...
CVE-2025-1399LOW3.1Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buff...
CVE-2025-3766MEDIUM5.4The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil...
CVE-2025-4335HIGH8.8The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and...
CVE-2025-4220MEDIUM6.4The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' ...
CVE-2025-4055MEDIUM6.4The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' s...
CVE-2025-4054MEDIUM6.1The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights fu...
CVE-2025-3924MEDIUM5.3The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its public...
CVE-2025-3921HIGH8.2The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-3860MEDIUM6.4The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in al...
CVE-2025-3853MEDIUM6.5The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2....
CVE-2025-3852HIGH8.8The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2....
CVE-2025-3851MEDIUM4.3The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Dire...
CVE-2025-3844CRITICAL9.8The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to...
CVE-2025-2821MEDIUM5.3The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-3218MEDIUM5.4IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation ...
CVE-2025-0856HIGH7.3The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ...
CVE-2025-0855CRITICAL9.8The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via ...
CVE-2025-4372HIGH8.8Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now