2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10437CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electroni...
CVE-2025-64408MEDIUM6.3Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controlla...
CVE-2025-13395HIGH7.3A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted el...
CVE-2025-12472HIGH7.1An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git direct...
CVE-2025-58412MEDIUM6.1A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0...
CVE-2025-11230HIGH7.5Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially ...
CVE-2025-0351Rejected reason: Voluntarily withdrawn
CVE-2025-11446MEDIUM6.5Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know...
CVE-2025-13206MEDIUM6.1The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2025-13035HIGH8The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. ...
CVE-2025-12484HIGH7.2The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for...
CVE-2025-13085MEDIUM4.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta...
CVE-2025-12535MEDIUM5.3The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and includi...
CVE-2025-12056HIGH8.3Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.
CVE-2025-11243HIGH8.3Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo...
CVE-2025-13145HIGH7.2The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in al...
CVE-2025-13054MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2025-12878MEDIUM6.4The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-12842MEDIUM5.3The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sendi...
CVE-2025-12822MEDIUM4.3The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-12814MEDIUM5.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect ...
CVE-2025-12751MEDIUM4.3The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-12710MEDIUM6.4The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shor...
CVE-2025-12646HIGH7.5The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u...
CVE-2025-12359MEDIUM5.4The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now