2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11634MEDIUM4.6A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component U...
CVE-2025-11633MEDIUM5.9A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_t...
CVE-2025-52615MEDIUM5.3HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser def...
CVE-2025-52614MEDIUM4.3HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to in...
CVE-2025-31969MEDIUM6.1HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources ...
CVE-2025-31992MEDIUM4.6HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters...
CVE-2025-11628MEDIUM4.7A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This a...
CVE-2025-11606MEDIUM6.3A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The...
CVE-2025-9975MEDIUM6.8The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5...
CVE-2025-9950MEDIUM4.9The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and...
CVE-2025-9947MEDIUM4.9The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versio...
CVE-2025-9626MEDIUM4.3The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-9621MEDIUM4.3The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-8682MEDIUM4.3The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th...
CVE-2025-8484MEDIUM5.3The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 throug...
CVE-2025-7652MEDIUM6.4The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode...
CVE-2025-58301MEDIUM5.5Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ...
CVE-2025-58300MEDIUM5.5Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ...
CVE-2025-58293MEDIUM5.5Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe...
CVE-2025-58289MEDIUM5.5Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe...
CVE-2025-10376MEDIUM4.3The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-10375MEDIUM4.3The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-10190MEDIUM6.4The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco...
CVE-2025-10175MEDIUM6.5The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and ...
CVE-2025-10167MEDIUM6.4The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now