2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12025MEDIUM4.4The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2025-12003HIGH8.2A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact...
CVE-2025-13644HIGH7.5MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue a...
CVE-2025-13643MEDIUM6.5A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are bein...
CVE-2025-12742HIGH7.5A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Ter...
CVE-2025-64730MEDIUM6.1Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary s...
CVE-2025-64304MEDIUM5.1"FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptogra...
CVE-2025-62497MEDIUM6.5Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a speciall...
CVE-2025-13559CRITICAL9.8The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. ...
CVE-2025-13558MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-13507HIGH7.1Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON doc...
CVE-2025-13068HIGH7.2The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i...
CVE-2025-12893MEDIUM5.4Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align...
CVE-2025-66187Rejected reason: Not used
CVE-2025-66186Rejected reason: Not used
CVE-2025-66185Rejected reason: Not used
CVE-2025-66184Rejected reason: Not used
CVE-2025-66183Rejected reason: Not used
CVE-2025-66182Rejected reason: Not used
CVE-2025-66181Rejected reason: Not used
CVE-2025-66180Rejected reason: Not used
CVE-2025-66179Rejected reason: Not used
CVE-2025-10646MEDIUM4.3The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capabil...
CVE-2025-6389CRITICAL9.8The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8...
CVE-2025-59373HIGH8.5A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now