2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12963CRITICAL9.8The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable ...
CVE-2025-12883MEDIUM5.3The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versi...
CVE-2025-12834MEDIUM6.1The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
CVE-2025-12830MEDIUM6.4The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in a...
CVE-2025-12824HIGH8.8The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ...
CVE-2025-12783MEDIUM4.3The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2025-12650MEDIUM6.4The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter...
CVE-2025-13886HIGH7.5The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ...
CVE-2025-13839MEDIUM6.4The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' s...
CVE-2025-13670MEDIUM6.7The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability
CVE-2025-13669MEDIUM6.7Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hi...
CVE-2025-13665MEDIUM6.7The System Console Utility for Windows is vulnerable to a DLL planting vulnerability
CVE-2025-13053LOW3.7When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification ca...
CVE-2025-13052MEDIUM5.9When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL c...
CVE-2025-10451HIGH8.2Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
CVE-2025-67779HIGH7.5It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den...
CVE-2025-67780MEDIUM4.2SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un...
CVE-2025-66452MEDIUM6.1LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing...
CVE-2025-66451MEDIUM6.5LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests...
CVE-2025-66450MEDIUM5.4LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic...
CVE-2025-66446HIGH7.5MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow...
CVE-2025-66419CRITICAL10MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to ...
CVE-2025-64721CRITICAL10Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1....
CVE-2025-34506HIGH8.8WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator...
CVE-2025-34504MEDIUM6.1KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now