2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10037MEDIUM4.9The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_f...
CVE-2025-10036MEDIUM4.9The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function i...
CVE-2025-9044MEDIUM6.4The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up...
CVE-2025-11000MEDIUM5.5A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file ...
CVE-2025-10745MEDIUM5.3The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in ...
CVE-2025-10377MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-10999MEDIUM5.5A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt o...
CVE-2025-10998MEDIUM5.5A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReacti...
CVE-2025-8906MEDIUM6.4The Widgets for Tiktok Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trustind...
CVE-2025-8200MEDIUM6.4The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-10992MEDIUM5.5A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unkno...
CVE-2025-10752MEDIUM4.3The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve...
CVE-2025-10178MEDIUM6.4The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featu...
CVE-2025-60251MEDIUM5Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
CVE-2025-60250MEDIUM4.7Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554...
CVE-2025-10981MEDIUM6.5A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXl...
CVE-2025-10980MEDIUM6.5A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/p...
CVE-2025-56769MEDIUM6.5An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that le...
CVE-2025-10979MEDIUM6.5A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/ro...
CVE-2025-10978MEDIUM6.5A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /s...
CVE-2025-10977MEDIUM5.3A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteB...
CVE-2025-10976MEDIUM5.3A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/get...
CVE-2025-10975MEDIUM6.3A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects...
CVE-2025-10974MEDIUM6.3A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects th...
CVE-2025-59402MEDIUM5.4Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehos...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now