2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52795HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Cro...
CVE-2025-52794HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Creative-Solutions Creative Contact Form sexy-contact-form allows Sto...
CVE-2025-52793HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Esselink.nu Esselink.nu Settings esselinknu-settings allows Reflected...
CVE-2025-52792HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows...
CVE-2025-52791HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-ma...
CVE-2025-52790HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter wp-downloadcounter allows Stored XSS.This is...
CVE-2025-52789HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress chordpress allows Stored XSS.This issue a...
CVE-2025-52784HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hideoguchi Bluff Post bluff-post allows Stored XSS.This issue affects...
CVE-2025-52783HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in themelocation Change Cart button Colors WooCommerce wc-style allows S...
CVE-2025-52782HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in King Rayhan Scroll...
CVE-2025-52781HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Beee TinyNav tinynav allows Stored XSS.This issue affects TinyNav: fr...
CVE-2025-52780HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mohammad Parsa Logo Manager For Samandehi samandehi-logo-manager allo...
CVE-2025-52772HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Adnan Haque (a11n) Virtual Moderator allows Cross-Site Scripting (XSS...
CVE-2025-52715HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-52708HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49873HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi e...
CVE-2025-48705HIGH7.5An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a cra...
CVE-2025-32879HIGH8.8An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bl...
CVE-2025-32753HIGH7.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used i...
CVE-2025-6337HIGH8.8A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared...
CVE-2025-4102HIGH7.2The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2025-6335HIGH7.2A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing ...
CVE-2025-6334HIGH8.8A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function...
CVE-2025-6333HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects...
CVE-2025-6332HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affecte...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now