2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41363 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing... |
| CVE-2025-41362 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st... |
| CVE-2025-5757 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec... |
| CVE-2025-5727 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This af... |
| CVE-2025-5703 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versio... |
| CVE-2025-5699 | MEDIUM | 5.5 | 0.2% | Jun 6, 2025 | The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all vers... |
| CVE-2025-5686 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode... |
| CVE-2025-5586 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-5565 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all... |
| CVE-2025-5563 | MEDIUM | 6.5 | 0.3% | Jun 6, 2025 | The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, a... |
| CVE-2025-5541 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcod... |
| CVE-2025-5538 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' sho... |
| CVE-2025-5536 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortc... |
| CVE-2025-5534 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-5533 | MEDIUM | 6.4 | 0.2% | Jun 6, 2025 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcod... |
| CVE-2025-5019 | MEDIUM | 5.4 | 0.1% | Jun 6, 2025 | The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable... |
| CVE-2025-4966 | MEDIUM | 6.1 | 0.1% | Jun 6, 2025 | The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-4964 | MEDIUM | 4.9 | 0.3% | Jun 6, 2025 | The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter ... |
| CVE-2025-48910 | MEDIUM | 5.5 | 0.1% | Jun 6, 2025 | Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect avail... |
| CVE-2025-48908 | MEDIUM | 6.7 | 0.1% | Jun 6, 2025 | Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerabili... |
| CVE-2025-48907 | MEDIUM | 6.2 | 0.1% | Jun 6, 2025 | Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availab... |
| CVE-2025-48904 | MEDIUM | 6.2 | 0.1% | Jun 6, 2025 | Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerabi... |
| CVE-2025-48902 | MEDIUM | 6.6 | 0.1% | Jun 6, 2025 | Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this... |
| CVE-2025-2935 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Requ... |
| CVE-2025-5726 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now