2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59532HIGH8.6Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox conf...
CVE-2025-10815HIGH8.8A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the fil...
CVE-2025-10814HIGH8.8A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown fun...
CVE-2025-59527HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side...
CVE-2025-8892HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili...
CVE-2025-59588HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59572HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Fo...
CVE-2025-59570HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min...
CVE-2025-59430HIGH8.2Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitiz...
CVE-2025-58973HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58956HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-...
CVE-2025-58690HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect doliconnect allows Stored XSS.This issue affect...
CVE-2025-58688HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stor...
CVE-2025-58687HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin current-age allows Stored XSS.This is...
CVE-2025-58686HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect...
CVE-2025-58677HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website...
CVE-2025-58676HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER horizontal-slider allows Stored XSS.T...
CVE-2025-58671HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auc...
CVE-2025-58670HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection wp-content-protection allow...
CVE-2025-58662HIGH7.2Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injectio...
CVE-2025-58657HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid grid allows Stored XSS.This issue affects Grid: from ...
CVE-2025-58270HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cros...
CVE-2025-58268HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator wpmk-pdf-generator allows Stored XSS.This iss...
CVE-2025-58267HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Aftabul Islam Stock Message stock-message allows Stored XSS.This issu...
CVE-2025-58262HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPDirectoryKit Sweet Energy Efficiency sweet-energy-efficiency allows...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now