2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32427MEDIUM5.4Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or...
CVE-2025-32426MEDIUM5.4Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into t...
CVE-2025-3439CRITICAL9.8The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ...
CVE-2025-3422MEDIUM6.3The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress...
CVE-2025-3421MEDIUM6.1The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ...
CVE-2025-2575MEDIUM5.4The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2025-2541MEDIUM5.4The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2025-23391CRITICAL9.1A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password ...
CVE-2025-23389HIGH8.4A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML...
CVE-2025-23388HIGH8.2A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: fro...
CVE-2025-23387MEDIUM5.3A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users...
CVE-2025-31932HIGH8.8Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrar...
CVE-2025-31362LOW3.7Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtaine...
CVE-2025-2128MEDIUM6.5The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter...
CVE-2025-3434HIGH7.2The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in al...
CVE-2025-32681HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log ...
CVE-2025-32672HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32671HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Sci...
CVE-2025-32663HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32656HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32654HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32650HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Acces...
CVE-2025-32633HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset...
CVE-2025-32632HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Autom...
CVE-2025-32631HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in oxygensuite Oxygen MyDat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now