2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-28966HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive recent-posts-slider-respons...
CVE-2025-28964HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue...
CVE-2025-28958HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar bg-orthodox-calendar allows Stor...
CVE-2025-28954HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp backwp allows Path Traversal.This issue affects Backwp...
CVE-2025-28950HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author post-author allows Stored XSS.This issue af...
CVE-2025-28948HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected...
CVE-2025-26590HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nir Complete Googl...
CVE-2025-5763HIGH8.8A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerabili...
CVE-2025-5762HIGH7.5A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. Affe...
CVE-2025-5761HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. Thi...
CVE-2025-48329HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Real Ti...
CVE-2025-47584HIGH7.5Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a throu...
CVE-2025-41361HIGH8.3Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly h...
CVE-2025-41360HIGH8.7Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The device is vulnerable...
CVE-2025-39358HIGH8.8Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Inject...
CVE-2025-5758HIGH7.3A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This a...
CVE-2025-5755HIGH7.3A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical...
CVE-2025-5192HIGH7.5A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource ...
CVE-2025-48784HIGH7.5A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 a...
CVE-2025-48783HIGH7.5An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Mana...
CVE-2025-48781HIGH7.5An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Ma...
CVE-2025-5739HIGH8.8A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part...
CVE-2025-5738HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is...
CVE-2025-5737HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulne...
CVE-2025-5736HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now