2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68739——In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: hisi: Fix potential UAF in OPP handli...
CVE-2025-68738——In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix null pointer deref in mt799...
CVE-2025-68737——In the Linux kernel, the following vulnerability has been resolved: arm64/pageattr: Propagate return value from __chang...
CVE-2025-68736HIGH8.8In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories ...
CVE-2025-68735HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Prevent potential UAF in group creatio...
CVE-2025-68608HIGH7.5Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-68606MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post al...
CVE-2025-68605MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post G...
CVE-2025-68603MEDIUM5.4Missing Authorization vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows Exploiting Incorrectl...
CVE-2025-68602MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Strip...
CVE-2025-68601MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations ...
CVE-2025-68600MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Reques...
CVE-2025-68599MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Embeds For YouTube...
CVE-2025-68598MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team...
CVE-2025-68597MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interact...
CVE-2025-68596MEDIUM5.3Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Co...
CVE-2025-68595MEDIUM5.3Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiti...
CVE-2025-68594MEDIUM5.3Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-o...
CVE-2025-68593MEDIUM5.4Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access...
CVE-2025-68592MEDIUM4.3Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access...
CVE-2025-68591MEDIUM5.4Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly C...
CVE-2025-68590HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integrat...
CVE-2025-68589MEDIUM5.3Missing Authorization vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Exploiting Inc...
CVE-2025-68588MEDIUM4.3Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control...
CVE-2025-68587MEDIUM4.3Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Securi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now