2025 CVE Vulnerabilities

45,294 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4170MEDIUM6.4The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr'...
CVE-2025-4168MEDIUM6.4The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode...
CVE-2025-47229MEDIUM5.5libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion fa...
CVE-2025-3918CRITICAL9.8The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg...
CVE-2025-3779MEDIUM6.4The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all ve...
CVE-2025-46723HIGH7.8OpenVM is a performant and modular zkVM framework built for customization and extensibility. In version 1.0.0, OpenVM is...
CVE-2025-21572MEDIUM6.1OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens thr...
CVE-2025-4218HIGH7.8A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulne...
CVE-2025-4215LOW3.7A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is t...
CVE-2025-47226LOW3.3Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
CVE-2025-0782Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-4214CRITICAL9.8A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue af...
CVE-2025-4213CRITICAL9.8A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulner...
CVE-2025-46332MEDIUM6.5Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 ...
CVE-2025-45800CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the...
CVE-2025-3879HIGH8.8Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued ...
CVE-2025-4210HIGH7.3A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function Handl...
CVE-2025-4166MEDIUM6.5Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in...
CVE-2025-44877CRITICAL9.8Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via...
CVE-2025-44872CRITICAL9.8Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via...
CVE-2025-44868CRITICAL9.8Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm....
CVE-2025-3927CRITICAL9.8Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t...
CVE-2025-37798HIGH7.8In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_r...
CVE-2025-37797HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class h...
CVE-2025-1884HIGH7.8Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now