2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47333MEDIUM6.6Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47332MEDIUM6.4Memory corruption while processing a config call from userspace.
CVE-2025-47331MEDIUM6.1Information disclosure while processing a firmware event.
CVE-2025-47330MEDIUM5.5Transient DOS while parsing video packets received from the video firmware.
CVE-2025-32300HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studi...
CVE-2025-31964MEDIUM4.9Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged ...
CVE-2025-31963LOW3.3Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2...
CVE-2025-31962MEDIUM4.3Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic...
CVE-2025-31643HIGH8.8Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC...
CVE-2025-15474MEDIUM5.3AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticate...
CVE-2025-15472HIGH7.3A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of ...
CVE-2025-15158HIGH8.8The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in ...
CVE-2025-15058MEDIUM6.4The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' ...
CVE-2025-15018CRITICAL9.8The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to...
CVE-2025-15000MEDIUM4.4The Page Keys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_key’ parameter in all vers...
CVE-2025-14999MEDIUM4.3The Latest Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-14904MEDIUM4.3The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i...
CVE-2025-14901MEDIUM6.5The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing ...
CVE-2025-14891MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayN...
CVE-2025-14888MEDIUM4.4The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value fi...
CVE-2025-14887MEDIUM4.4The twinklesmtp – Email Service Provider For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-14875MEDIUM6.1The HBLPAY Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2025-14867MEDIUM6.5The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'so...
CVE-2025-14845MEDIUM4.3The NS IE Compatibility Fixer plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up...
CVE-2025-14842MEDIUM6.1The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files wi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now