2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8780MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero ...
CVE-2025-8779MEDIUM6.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-8687MEDIUM6.4The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image ...
CVE-2025-8617MEDIUM6.4The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_...
CVE-2025-8199MEDIUM6.4The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee...
CVE-2025-8195MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co...
CVE-2025-7960MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing...
CVE-2025-7058MEDIUM6.4The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in a...
CVE-2025-67871——Rejected reason: Not used
CVE-2025-67870——Rejected reason: Not used
CVE-2025-67869——Rejected reason: Not used
CVE-2025-67868——Rejected reason: Not used
CVE-2025-67867——Rejected reason: Not used
CVE-2025-67866——Rejected reason: Not used
CVE-2025-67865——Rejected reason: Not used
CVE-2025-67864——Rejected reason: Not used
CVE-2025-67863——Rejected reason: Not used
CVE-2025-36754CRITICAL9.3The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication check...
CVE-2025-36753CRITICAL9.8The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to ...
CVE-2025-36752CRITICAL9.8Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows si...
CVE-2025-36751CRITICAL9.4Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker wi...
CVE-2025-36750MEDIUM5.4ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be di...
CVE-2025-36748MEDIUM5.4ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScr...
CVE-2025-36747CRITICAL9.8ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish ...
CVE-2025-14620CRITICAL9.8A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now