2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11956HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-10955MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft...
CVE-2025-11268MEDIUM4.3The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i...
CVE-2025-12360MEDIUM4.3The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to...
CVE-2025-10259MEDIUM5.3Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Co...
CVE-2025-12471MEDIUM6.1The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2025-9338HIGH7.3A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability...
CVE-2025-12560MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in...
CVE-2025-61994MEDIUM5.4Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing craft...
CVE-2025-12563MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an ...
CVE-2025-11271MEDIUM5.3The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including...
CVE-2025-64480Rejected reason: Not used
CVE-2025-64479Rejected reason: Not used
CVE-2025-64478Rejected reason: Not used
CVE-2025-64477Rejected reason: Not used
CVE-2025-64476Rejected reason: Not used
CVE-2025-64475Rejected reason: Not used
CVE-2025-64474Rejected reason: Not used
CVE-2025-64473Rejected reason: Not used
CVE-2025-64472Rejected reason: Not used
CVE-2025-10691MEDIUM4.3The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-10683MEDIUM4.9The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions ...
CVE-2025-64171HIGH8.7MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n...
CVE-2025-64164CRITICAL9.8Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly fi...
CVE-2025-64163CRITICAL9.8DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now