2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3890MEDIUM5.4The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w...
CVE-2025-3889MEDIUM5.3The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2025-3874MEDIUM6.5The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2025-1529MEDIUM6.4The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all v...
CVE-2025-4162CRITICAL9.8A vulnerability classified as critical was found in PCMan FTP Server up to 2.0.7. This vulnerability affects unknown cod...
CVE-2025-4161CRITICAL9.8A vulnerability classified as critical has been found in PCMan FTP Server up to 2.0.7. This affects an unknown part of t...
CVE-2025-27007CRITICAL9.8Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This i...
CVE-2025-4160CRITICAL9.8A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been rated as critical. Affected by this issue is some...
CVE-2025-4159CRITICAL9.8A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been declared as critical. Affected by this vulnerabil...
CVE-2025-4158CRITICAL9.8A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been classified as critical. Affected is an unknown fu...
CVE-2025-4157HIGH8.8A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unkn...
CVE-2025-4156HIGH8.8A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe...
CVE-2025-4155HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unkn...
CVE-2025-47154CRITICAL9LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-a...
CVE-2025-4154HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affect...
CVE-2025-4153CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Park Ticketing Management System 2.0. Affected by this vu...
CVE-2025-4100MEDIUM6.4The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_ma...
CVE-2025-47153MEDIUM6.5Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_2...
CVE-2025-3521MEDIUM6.4The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vul...
CVE-2025-4152CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an ...
CVE-2025-4151CRITICAL9.8A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue a...
CVE-2025-3504MEDIUM4.8The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high...
CVE-2025-3503MEDIUM4.8The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high...
CVE-2025-3502MEDIUM4.8The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high...
CVE-2025-4150CRITICAL9.8A vulnerability was found in Netgear EX6200 1.0.3.94. It has been declared as critical. This vulnerability affects the f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now