2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23250CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a r...
CVE-2025-23249CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote co...
CVE-2025-29547HIGH7In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service becaus...
CVE-2025-23176HIGH8.8CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-1951MEDIUM6.7IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute comman...
CVE-2025-1950HIGH7.8IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute comman...
CVE-2025-28034CRITICAL9.8TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51...
CVE-2025-28033HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51...
CVE-2025-28032HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51...
CVE-2025-23175MEDIUM6.1Multiple XSS (CWE-79)
CVE-2025-3472CRITICAL9.8The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...
CVE-2025-3458MEDIUM5.4The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter i...
CVE-2025-3457MEDIUM5.4The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortc...
CVE-2025-2092HIGH7.5Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 ...
CVE-2025-46254MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi...
CVE-2025-46253MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit g...
CVE-2025-46252HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Messag...
CVE-2025-46251HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forg...
CVE-2025-46250MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUF...
CVE-2025-46249HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor a...
CVE-2025-46247CRITICAL9.8Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Acces...
CVE-2025-46246HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Reques...
CVE-2025-46245HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site ...
CVE-2025-46244CRITICAL9.8Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Explo...
CVE-2025-46243HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abando...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now