2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60262CRITICAL9.8An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi...
CVE-2025-59379HIGH7.5DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information f...
CVE-2025-14979HIGH7.8AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege...
CVE-2025-46696MEDIUM6.7Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi...
CVE-2025-14026HIGH7.8Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5...
CVE-2025-9637MEDIUM6.5The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access ...
CVE-2025-9318MEDIUM6.5The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2025-14552MEDIUM6.4The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode...
CVE-2025-9294MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of...
CVE-2025-5919MEDIUM6.5The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-13964MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2025-13766MEDIUM5.4The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-14371MEDIUM4.3The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m...
CVE-2025-13812MEDIUM4.3The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2025-12067MEDIUM6.4The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C...
CVE-2025-4776MEDIUM6.4The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all ...
CVE-2025-13215MEDIUM5.3The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-15001CRITICAL9.8The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...
CVE-2025-14997HIGH8.8The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic...
CVE-2025-14996CRITICAL9.8The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun...
CVE-2025-14441MEDIUM4.3The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th...
CVE-2025-14438MEDIUM6.4The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2025-14120MEDIUM6.4The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2025-14153MEDIUM6.5The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '...
CVE-2025-14034MEDIUM5.3The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now