2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32044HIGH7.5A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—i...
CVE-2025-28076MEDIUM6.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated at...
CVE-2025-3634MEDIUM4.3A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completin...
CVE-2025-28354MEDIUM6.5An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a ...
CVE-2025-3912MEDIUM5.3The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized acc...
CVE-2025-2986MEDIUM5.4IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged...
CVE-2025-2470CRITICAL9.8The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, ...
CVE-2025-1565HIGH7.5The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 v...
CVE-2025-3870MEDIUM6.1The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-1279HIGH8.8The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg...
CVE-2025-46535MEDIUM5.4Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly C...
CVE-2025-46482MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Qui...
CVE-2025-46617HIGH7.2Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification...
CVE-2025-46616CRITICAL9.9Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. T...
CVE-2025-3868MEDIUM6.1The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject'...
CVE-2025-3867MEDIUM6.1The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-3866MEDIUM6.1The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-3743MEDIUM5.3The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to...
CVE-2025-2238HIGH8.8The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to...
CVE-2025-46613HIGH7.5OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after...
CVE-2025-3923MEDIUM5.3The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2025-3861MEDIUM5.4The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modifi...
CVE-2025-3511HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remot...
CVE-2025-2580MEDIUM4.9The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a...
CVE-2025-0671MEDIUM6.1The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now