2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6783HIGH7.5The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() functi...
CVE-2025-6782HIGH7.5The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm(...
CVE-2025-6586HIGH7.2The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-6238HIGH8The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth imp...
CVE-2025-5956HIGH8.1The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authoriz...
CVE-2025-5953HIGH8.8The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization...
CVE-2025-5322HIGH7.2The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2025-53367HIGH8.4DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version ...
CVE-2025-49826HIGH7.5Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, ...
CVE-2025-53369HIGH8.6Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descri...
CVE-2025-34088HIGH8.8An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php ...
CVE-2025-34087HIGH8.8An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allow...
CVE-2025-34086HIGH8.8Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achi...
CVE-2025-6926HIGH8.8Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authenti...
CVE-2025-6073HIGH8.2Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the u...
CVE-2025-6072HIGH8.2Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the...
CVE-2025-53501HIGH8.8Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functio...
CVE-2025-5961HIGH7.2The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads...
CVE-2025-50263HIGH8.1Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.
CVE-2025-50262HIGH7.5Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.
CVE-2025-50260HIGH7.5Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn para...
CVE-2025-50258HIGH8.1Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.
CVE-2025-2932HIGH8.8The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t...
CVE-2025-27459HIGH7.5The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, th...
CVE-2025-27458HIGH7.5The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now