2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12158CRITICAL9.8The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec...
CVE-2025-12157MEDIUM5.3The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-12156MEDIUM4.3The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un...
CVE-2025-12065MEDIUM4.4The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter...
CVE-2025-11890HIGH7.5The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versi...
CVE-2025-11812MEDIUM6.4The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t...
CVE-2025-11758MEDIUM6.5The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization ...
CVE-2025-11753MEDIUM4.4The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-11733HIGH7.2The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver...
CVE-2025-11724HIGH8.8The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all ...
CVE-2025-11704HIGH7.5The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 v...
CVE-2025-10896HIGH8.8Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of...
CVE-2025-47370MEDIUM6.5Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
CVE-2025-47368HIGH7.8Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.
CVE-2025-47367HIGH7.8Memory corruption while accessing a buffer during IOCTL processing.
CVE-2025-47365HIGH7.8Memory corruption while processing large input data from a remote source via a communication interface.
CVE-2025-47362MEDIUM6.1Information disclosure while processing message from client with invalid payload.
CVE-2025-47361HIGH7.8Memory corruption when triggering a subsystem crash with an out-of-range identifier.
CVE-2025-47360HIGH7.8Memory corruption while processing client message during device management.
CVE-2025-47357HIGH7.8Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
CVE-2025-47353HIGH7.8Memory corruption while processing request sent from GVM.
CVE-2025-47352HIGH7.8Memory corruption while processing audio streaming operations.
CVE-2025-27074HIGH7.8Memory corruption while processing a GP command response.
CVE-2025-27070HIGH7.8Memory corruption while performing encryption and decryption commands.
CVE-2025-27064MEDIUM6.1Information disclosure while registering commands from clients with diag through diagHal.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now