2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-28136MEDIUM6.5TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
CVE-2025-3608MEDIUM6.5A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially lea...
CVE-2025-32946MEDIUM5.3This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. Th...
CVE-2025-32945MEDIUM4.3The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. Th...
CVE-2025-32944MEDIUM6.5The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner....
CVE-2025-32103MEDIUM5CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ ...
CVE-2025-32102MEDIUM5CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=t...
CVE-2025-32929HIGH7.5Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-bar...
CVE-2025-31011HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers S...
CVE-2025-30985CRITICAL9.8Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affe...
CVE-2025-30965MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue aff...
CVE-2025-30964MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forger...
CVE-2025-30962HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster ...
CVE-2025-26992HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing...
CVE-2025-26990MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server...
CVE-2025-26982MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächle...
CVE-2025-26959HIGH8.8Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue ...
CVE-2025-26958HIGH7.5Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrain...
CVE-2025-26955MEDIUM4.3Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured...
CVE-2025-26954HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooE...
CVE-2025-26944HIGH7.5Missing Authorization vulnerability in Crocoblock JetPopup jet-popup allows Accessing Functionality Not Properly Constra...
CVE-2025-26942HIGH7.5Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Const...
CVE-2025-26894HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26889HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-26745MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Element...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now