2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13747MEDIUM6.4The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode f...
CVE-2025-13440MEDIUM5.3The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to...
CVE-2025-13408MEDIUM4.3The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to C...
CVE-2025-13366MEDIUM4.3The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-13363MEDIUM4.3The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2...
CVE-2025-13334HIGH8.1The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi...
CVE-2025-13320MEDIUM6.8The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, ...
CVE-2025-13314MEDIUM5.3The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable ...
CVE-2025-12968HIGH8.8The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and...
CVE-2025-12963CRITICAL9.8The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable ...
CVE-2025-12883MEDIUM5.3The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versi...
CVE-2025-12834MEDIUM6.1The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
CVE-2025-12830MEDIUM6.4The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in a...
CVE-2025-12824HIGH8.8The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ...
CVE-2025-12783MEDIUM4.3The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2025-12650MEDIUM6.4The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter...
CVE-2025-13886HIGH7.5The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ...
CVE-2025-13839MEDIUM6.4The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' s...
CVE-2025-13670MEDIUM6.7The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability
CVE-2025-13669MEDIUM6.7Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hi...
CVE-2025-13665MEDIUM6.7The System Console Utility for Windows is vulnerable to a DLL planting vulnerability
CVE-2025-13053LOW3.7When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification ca...
CVE-2025-13052MEDIUM5.9When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL c...
CVE-2025-10451HIGH8.2Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
CVE-2025-67779HIGH7.5It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now