2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3479MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Repl...
CVE-2025-3453MEDIUM5.3The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect...
CVE-2025-26478MEDIUM6.5Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker...
CVE-2025-26477HIGH8.8Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with re...
CVE-2025-29931MEDIUM6.3A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not...
CVE-2025-2197MEDIUM4.3Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service av...
CVE-2025-2188CRITICAL9.1There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co...
CVE-2025-1532CRITICAL9.1Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affec...
CVE-2025-3615MEDIUM6.4The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in ...
CVE-2025-3113CRITICAL9A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database con...
CVE-2025-2903HIGH8.5An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Lo...
CVE-2025-3295MEDIUM4.9The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. T...
CVE-2025-3294HIGH7.2The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all ver...
CVE-2025-1525LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-1524LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-1523LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-43717MEDIUM5.4In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and ...
CVE-2025-43715HIGH8.1Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM dur...
CVE-2025-31340CRITICAL9.9A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Informa...
CVE-2025-31339MEDIUM5.3An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro ...
CVE-2025-31338MEDIUM6.9A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 thr...
CVE-2025-43708HIGH7.5VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMa...
CVE-2025-1290HIGH8.1A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4...
CVE-2025-43704MEDIUM4.7Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authenticatio...
CVE-2025-2400Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now