2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15271HIGH8.8FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability al...
CVE-2025-15270HIGH8.8FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability al...
CVE-2025-15269HIGH8.8FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attacker...
CVE-2025-14783MEDIUM4.3The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and includi...
CVE-2025-69277MEDIUM4.5libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_e...
CVE-2025-68885HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS...
CVE-2025-49354HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category recent-posts-f...
CVE-2025-49353HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path noindex-by-path allows Stored XSS.This i...
CVE-2025-49345HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue aff...
CVE-2025-49344HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This ...
CVE-2025-49343HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in socialprofilr Social Profilr social-profilr-display-social-network-pr...
CVE-2025-49342HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affec...
CVE-2025-14434MEDIUM5.3The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints su...
CVE-2025-13029HIGH7.5The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its RE...
CVE-2025-59137HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behan...
CVE-2025-49346HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allo...
CVE-2025-15375HIGH8.8A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/a...
CVE-2025-15374MEDIUM5.4A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application...
CVE-2025-15373MEDIUM4.3A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file appli...
CVE-2025-15372MEDIUM4.8A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing ...
CVE-2025-15223MEDIUM6.1A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an u...
CVE-2025-68131HIGH7.5cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting ...
CVE-2025-15371HIGH7.8A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. A...
CVE-2025-11964LOW1.9On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that U...
CVE-2025-11961LOW1.9pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now