2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62934HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issu...
CVE-2025-62933HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.T...
CVE-2025-62896HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows St...
CVE-2025-62886HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored X...
CVE-2025-12201HIGH7.2A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1....
CVE-2025-11989HIGH8.1GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18...
CVE-2025-11447HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 1...
CVE-2025-10497HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and ...
CVE-2025-8709HIGH7.3A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite st...
CVE-2025-12221HIGH8.8Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-9322HIGH7.5The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is...
CVE-2025-8416HIGH7.5The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in ...
CVE-2025-4203HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() fun...
CVE-2025-10488HIGH8.1The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-12095HIGH8.8The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-11238HIGH7.2The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions ...
CVE-2025-34503HIGH7Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker ...
CVE-2025-34502HIGH7Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. ...
CVE-2025-34500HIGH7Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit...
CVE-2025-4106HIGH8.9An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable ...
CVE-2025-34293HIGH8.6GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API...
CVE-2025-60954HIGH8.3Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexit...
CVE-2025-62716HIGH8.1Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_pa...
CVE-2025-60735HIGH7.6PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
CVE-2025-60731HIGH7.6PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now