2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6783 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() functi... |
| CVE-2025-6782 | HIGH | 7.5 | 0.3% | Jul 4, 2025 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm(... |
| CVE-2025-6586 | HIGH | 7.2 | 1.1% | Jul 4, 2025 | The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-6238 | HIGH | 8 | 0.3% | Jul 4, 2025 | The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth imp... |
| CVE-2025-5956 | HIGH | 8.1 | 0.3% | Jul 4, 2025 | The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authoriz... |
| CVE-2025-5953 | HIGH | 8.8 | 0.4% | Jul 4, 2025 | The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization... |
| CVE-2025-5322 | HIGH | 7.2 | 0.6% | Jul 3, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2025-53367 | HIGH | 8.4 | 0.7% | Jul 3, 2025 | DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version ... |
| CVE-2025-49826 | HIGH | 7.5 | 0.8% | Jul 3, 2025 | Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, ... |
| CVE-2025-53369 | HIGH | 8.6 | 0.3% | Jul 3, 2025 | Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descri... |
| CVE-2025-34088 | HIGH | 8.8 | 5.1% | Jul 3, 2025 | An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php ... |
| CVE-2025-34087 | HIGH | 8.8 | 5.0% | Jul 3, 2025 | An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allow... |
| CVE-2025-34086 | HIGH | 8.8 | 2.1% | Jul 3, 2025 | Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achi... |
| CVE-2025-6926 | HIGH | 8.8 | 0.4% | Jul 3, 2025 | Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authenti... |
| CVE-2025-6073 | HIGH | 8.2 | 0.4% | Jul 3, 2025 | Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the u... |
| CVE-2025-6072 | HIGH | 8.2 | 0.3% | Jul 3, 2025 | Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the... |
| CVE-2025-53501 | HIGH | 8.8 | 0.3% | Jul 3, 2025 | Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functio... |
| CVE-2025-5961 | HIGH | 7.2 | 6.5% | Jul 3, 2025 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads... |
| CVE-2025-50263 | HIGH | 8.1 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter. |
| CVE-2025-50262 | HIGH | 7.5 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter. |
| CVE-2025-50260 | HIGH | 7.5 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn para... |
| CVE-2025-50258 | HIGH | 8.1 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter. |
| CVE-2025-2932 | HIGH | 8.8 | 0.7% | Jul 3, 2025 | The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t... |
| CVE-2025-27459 | HIGH | 7.5 | 0.2% | Jul 3, 2025 | The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, th... |
| CVE-2025-27458 | HIGH | 7.5 | 0.2% | Jul 3, 2025 | The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now