2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39377HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Hel...
CVE-2025-39360HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39359HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32921HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-44135MEDIUM6.5A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_upda...
CVE-2025-44134MEDIUM6.5A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/cla...
CVE-2025-29568MEDIUM4.8A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects ...
CVE-2025-43855HIGH8.7tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 1...
CVE-2025-30409MEDIUM5.5Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Prot...
CVE-2025-30408MEDIUM6.7Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2025-46421MEDIUM6.8A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorizatio...
CVE-2025-46420MEDIUM6.5A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when pars...
CVE-2025-27820HIGH7.5A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na...
CVE-2025-3872HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-...
CVE-2025-3832MEDIUM6.4The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in al...
CVE-2025-3793MEDIUM4.2The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu...
CVE-2025-3776HIGH8.3The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions ...
CVE-2025-3607HIGH8.8The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2025-3604CRITICAL9.8The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-3603CRITICAL9.8The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-3300HIGH7.2The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all version...
CVE-2025-3280MEDIUM6.5The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio...
CVE-2025-3101HIGH8.8The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2025-3065CRITICAL9.1The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct...
CVE-2025-3058HIGH8.8The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now