2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13456MEDIUM6.1The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the...
CVE-2025-13153MEDIUM6.1The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting...
CVE-2025-12685MEDIUM6.5The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica...
CVE-2025-15428HIGH8.8A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy of the file /goform/formRemo...
CVE-2025-15427Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...
CVE-2025-15426HIGH7.3A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/we...
CVE-2025-15425CRITICAL9.8A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/de...
CVE-2025-15424CRITICAL9.8A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_w...
CVE-2025-15423HIGH8.8A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the ...
CVE-2025-14998CRITICAL9.8The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...
CVE-2025-14047MEDIUM5.3The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User ...
CVE-2025-15422HIGH7.5A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/conn...
CVE-2025-15421CRITICAL9.8A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_wo...
CVE-2025-15420CRITICAL9.8A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent...
CVE-2025-15419MEDIUM5.5A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_ses...
CVE-2025-15418MEDIUM5.5A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_pars...
CVE-2025-15417MEDIUM5.5A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request o...
CVE-2025-15416MEDIUM5.4A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of...
CVE-2025-15415MEDIUM5.4A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil...
CVE-2025-15414MEDIUM4.7A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service...
CVE-2025-15413HIGH7.8A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m...
CVE-2025-15412HIGH7.8A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decom...
CVE-2025-15411HIGH7.8A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::Inse...
CVE-2025-69203HIGH8.8Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access req...
CVE-2025-68620CRITICAL9.1Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now