2025 CVE Vulnerabilities

45,294 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-1883HIGH7.8Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS...
CVE-2025-4204HIGH7.5The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versi...
CVE-2025-2605HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB...
CVE-2025-2488MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis In...
CVE-2025-2421CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Inj...
CVE-2025-1301MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Info...
CVE-2025-0427HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2025-0072HIGH7.8Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-2812CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics...
CVE-2025-47201MEDIUM5.4In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaSc...
CVE-2025-3514LOW3.5The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h...
CVE-2025-3513LOW3.5The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h...
CVE-2025-3488MEDIUM5.4The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher short...
CVE-2025-3438HIGH7.3The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege e...
CVE-2025-3858MEDIUM5.4The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all version...
CVE-2025-3748MEDIUM5.4The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu...
CVE-2025-3709CRITICAL9.8Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attacker...
CVE-2025-3708CRITICAL9.8Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remot...
CVE-2025-3707MEDIUM6.5The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject...
CVE-2025-3510MEDIUM5.4The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all ver...
CVE-2025-1327MEDIUM4.3The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2....
CVE-2025-1326MEDIUM4.3The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th...
CVE-2025-4179HIGH7.3The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check o...
CVE-2025-4177MEDIUM5.3The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on t...
CVE-2025-4131MEDIUM6.4The GmapsMania plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gmap shortcode in all ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now