2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12221HIGH8.8Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-9322HIGH7.5The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is...
CVE-2025-8416HIGH7.5The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in ...
CVE-2025-4203HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() fun...
CVE-2025-10488HIGH8.1The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-12095HIGH8.8The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-11238HIGH7.2The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions ...
CVE-2025-34503HIGH7Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker ...
CVE-2025-34502HIGH7Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. ...
CVE-2025-34500HIGH7Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit...
CVE-2025-4106HIGH8.9An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable ...
CVE-2025-34293HIGH8.6GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API...
CVE-2025-60954HIGH8.3Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexit...
CVE-2025-62716HIGH8.1Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_pa...
CVE-2025-60735HIGH7.6PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
CVE-2025-60731HIGH7.6PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
CVE-2025-60730HIGH7.6PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
CVE-2025-62714HIGH8.7Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project....
CVE-2025-60801HIGH8.2jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via ...
CVE-2025-60566HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60565HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60564HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60563HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60562HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formW...
CVE-2025-60561HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now