2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10129MEDIUM6.4The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-58299MEDIUM5.5Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may a...
CVE-2025-58298MEDIUM5.5Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may ...
CVE-2025-58297MEDIUM5.5Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availabili...
CVE-2025-58295MEDIUM5.5Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may aff...
CVE-2025-58292MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58291MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58290MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58288MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58287MEDIUM5.5Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect servi...
CVE-2025-58286MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-11594MEDIUM5.5A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f...
CVE-2025-11518MEDIUM5.3The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver...
CVE-2025-11254MEDIUM4.3The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in ...
CVE-2025-11167MEDIUM4.7The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulner...
CVE-2025-9496MEDIUM6.4The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modifie...
CVE-2025-9196MEDIUM5.3The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to S...
CVE-2025-11197MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ...
CVE-2025-10185MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderb...
CVE-2025-10048MEDIUM4.9The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up...
CVE-2025-58285MEDIUM5.5Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service c...
CVE-2025-58284MEDIUM5.5Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service...
CVE-2025-58283MEDIUM5.5Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service c...
CVE-2025-58282MEDIUM5.5Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service ...
CVE-2025-58278MEDIUM5.5Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now