2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14641HIGH7.2A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the...
CVE-2025-14640CRITICAL9.8A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function o...
CVE-2025-14639CRITICAL9.8A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file ...
CVE-2025-14638CRITICAL9.8A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects som...
CVE-2025-13832Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-14637CRITICAL9.8A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown...
CVE-2025-14636LOW3.7A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component htt...
CVE-2025-14623CRITICAL9.8A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown proc...
CVE-2025-14622CRITICAL9.8A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unkn...
CVE-2025-14621CRITICAL9.8A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the ...
CVE-2025-9873MEDIUM6.4The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,...
CVE-2025-9856MEDIUM6.4The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St...
CVE-2025-9488MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all ve...
CVE-2025-9218LOW3.7The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to...
CVE-2025-9207MEDIUM5.3The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2...
CVE-2025-9116MEDIUM5.8The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2025-8780MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero ...
CVE-2025-8779MEDIUM6.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-8687MEDIUM6.4The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image ...
CVE-2025-8617MEDIUM6.4The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_...
CVE-2025-8199MEDIUM6.4The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee...
CVE-2025-8195MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co...
CVE-2025-7960MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing...
CVE-2025-7058MEDIUM6.4The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in a...
CVE-2025-67871Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now