2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12586MEDIUM4.3The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v...
CVE-2025-12525MEDIUM5.3The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'locker...
CVE-2025-12043MEDIUM5.3The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-12040MEDIUM6.5The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t...
CVE-2025-12032MEDIUM4.4The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-12025MEDIUM4.4The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2025-13643MEDIUM6.5A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are bein...
CVE-2025-64730MEDIUM6.1Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary s...
CVE-2025-64304MEDIUM5.1"FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptogra...
CVE-2025-62497MEDIUM6.5Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a speciall...
CVE-2025-13558MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-12893MEDIUM5.4Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align...
CVE-2025-10646MEDIUM4.3The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capabil...
CVE-2025-65944MEDIUM5.1Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js appl...
CVE-2025-64506MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-64505MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-10144MEDIUM6.5The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri...
CVE-2025-63674MEDIUM6.8An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary c...
CVE-2025-54341MEDIUM5.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Ha...
CVE-2025-63498MEDIUM6.1alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
CVE-2025-48511MEDIUM5.5Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti...
CVE-2025-29933MEDIUM5.5Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a...
CVE-2025-0007MEDIUM5.7Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user s...
CVE-2025-64048MEDIUM6.1YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulner...
CVE-2025-64047MEDIUM6.1OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now