2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62746MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeFlavors Featur...
CVE-2025-61557HIGH7.5nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.
CVE-2025-15255CRITICAL9.8A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of th...
CVE-2025-15254HIGH8.8A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the ...
CVE-2025-15253HIGH8.8A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /gofo...
CVE-2025-15252HIGH8.8A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the fil...
CVE-2025-15251MEDIUM6.3A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot...
CVE-2025-15250MEDIUM4.7A security vulnerability has been detected in 08CMS Novel System up to 3.4. This issue affects some unknown processing o...
CVE-2025-15249MEDIUM5.1A weakness has been identified in zhujunliang3 work_platform up to 6bc5a50bb527ce27f7906d11ea6ec139beb79c31. This vulner...
CVE-2025-15248LOW3.5A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb46...
CVE-2025-14426MEDIUM4.3The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2025-15247CRITICAL9.8A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue...
CVE-2025-15246MEDIUM6.3A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function ...
CVE-2025-14509HIGH7.2The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions u...
CVE-2025-69093MEDIUM5.3Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configur...
CVE-2025-69092MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essent...
CVE-2025-69091MEDIUM4.3Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly...
CVE-2025-69089MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in autolistings Auto ...
CVE-2025-69088MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vidish Combo Offer...
CVE-2025-69034HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69033MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Fil...
CVE-2025-69032MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Inco...
CVE-2025-69031MEDIUM5.3Missing Authorization vulnerability in Skywarrior Arcane arcane allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-69030MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allow...
CVE-2025-69029MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Select-Themes Struktur struktur allows Exploiting Inco...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now