2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52790HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter wp-downloadcounter allows Stored XSS.This is...
CVE-2025-52789HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress chordpress allows Stored XSS.This issue a...
CVE-2025-52784HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hideoguchi Bluff Post bluff-post allows Stored XSS.This issue affects...
CVE-2025-52783HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in themelocation Change Cart button Colors WooCommerce wc-style allows S...
CVE-2025-52782HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in King Rayhan Scroll...
CVE-2025-52781HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Beee TinyNav tinynav allows Stored XSS.This issue affects TinyNav: fr...
CVE-2025-52780HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mohammad Parsa Logo Manager For Samandehi samandehi-logo-manager allo...
CVE-2025-52772HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Adnan Haque (a11n) Virtual Moderator allows Cross-Site Scripting (XSS...
CVE-2025-52715HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-52708HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49873HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi e...
CVE-2025-48705HIGH7.5An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a cra...
CVE-2025-32879HIGH8.8An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bl...
CVE-2025-32753HIGH7.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used i...
CVE-2025-6337HIGH8.8A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared...
CVE-2025-4102HIGH7.2The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2025-6335HIGH7.2A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing ...
CVE-2025-6334HIGH8.8A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function...
CVE-2025-6333HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects...
CVE-2025-6332HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affecte...
CVE-2025-6331HIGH8.8A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnera...
CVE-2025-6329HIGH8.1A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue...
CVE-2025-6328HIGH8.8A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the funct...
CVE-2025-6321HIGH8.8A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by th...
CVE-2025-6320HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System 1.0. Affected is...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now