2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0034MEDIUM4.7Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2025-0010MEDIUM6.1An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting...
CVE-2025-0009MEDIUM5.5A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentiall...
CVE-2025-10032MEDIUM6.1A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown fun...
CVE-2025-10029MEDIUM6.1A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown cod...
CVE-2025-10046MEDIUM4.9The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the '...
CVE-2025-10028MEDIUM6.1A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /i...
CVE-2025-6757MEDIUM6.4The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpw...
CVE-2025-9493MEDIUM6.4The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter ...
CVE-2025-9442MEDIUM6.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChanne...
CVE-2025-9126MEDIUM6.4The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ...
CVE-2025-8722MEDIUM6.4The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widge...
CVE-2025-8564MEDIUM6.4The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a...
CVE-2025-8149MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun...
CVE-2025-7045MEDIUM6.5The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on...
CVE-2025-9853MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2025-9085MEDIUM4.9The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version ...
CVE-2025-8360MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of...
CVE-2025-10003MEDIUM6.5The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ...
CVE-2025-9849MEDIUM6.4The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_...
CVE-2025-7368MEDIUM5.3The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information ...
CVE-2025-6067MEDIUM6.4The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-58373MEDIUM6.5Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul...
CVE-2025-58369MEDIUM5.3fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, a...
CVE-2025-10027MEDIUM6.1A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown func...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now