2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8998LOW3.1It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and i...
CVE-2025-7429MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-5317MEDIUM5.5An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 a...
CVE-2025-10714HIGH8.4AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala...
CVE-2025-8108MEDIUM6.7An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privileg...
CVE-2025-6779MEDIUM6.7An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privile...
CVE-2025-6571MEDIUM6A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.
CVE-2025-6298MEDIUM6.7ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escala...
CVE-2025-5718MEDIUM6.8The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be...
CVE-2025-5454MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote...
CVE-2025-5452MEDIUM6.6A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat...
CVE-2025-4645MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln...
CVE-2025-11855HIGH7.5The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportReques...
CVE-2025-11307HIGH8.8The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJA...
CVE-2025-11237MEDIUM5.3The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option va...
CVE-2025-12880MEDIUM5.4The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl...
CVE-2025-12813CRITICAL9.8The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2025-12754MEDIUM6.4The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost...
CVE-2025-12753MEDIUM6.4The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al...
CVE-2025-12711MEDIUM6.4The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google ...
CVE-2025-12672MEDIUM6.4The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the ...
CVE-2025-12671MEDIUM6.4The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon...
CVE-2025-12668MEDIUM6.4The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the...
CVE-2025-12667MEDIUM6.4The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th...
CVE-2025-12665MEDIUM4.3The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now