2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10065MEDIUM6.1A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file...
CVE-2025-10064MEDIUM6.1A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown proces...
CVE-2025-10063MEDIUM6.1A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of ...
CVE-2025-0034MEDIUM4.7Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2025-0010MEDIUM6.1An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting...
CVE-2025-0009MEDIUM5.5A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentiall...
CVE-2025-10032MEDIUM6.1A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown fun...
CVE-2025-10029MEDIUM6.1A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown cod...
CVE-2025-10046MEDIUM4.9The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the '...
CVE-2025-10028MEDIUM6.1A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /i...
CVE-2025-6757MEDIUM6.4The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpw...
CVE-2025-9493MEDIUM6.4The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter ...
CVE-2025-9442MEDIUM6.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChanne...
CVE-2025-9126MEDIUM6.4The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ...
CVE-2025-8722MEDIUM6.4The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widge...
CVE-2025-8564MEDIUM6.4The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a...
CVE-2025-8149MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun...
CVE-2025-7045MEDIUM6.5The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on...
CVE-2025-9853MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2025-9085MEDIUM4.9The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version ...
CVE-2025-8360MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of...
CVE-2025-10003MEDIUM6.5The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ...
CVE-2025-9849MEDIUM6.4The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_...
CVE-2025-7368MEDIUM5.3The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information ...
CVE-2025-6067MEDIUM6.4The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now