2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12597CRITICAL9.8A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability i...
CVE-2025-12596CRITICAL9.8A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of ...
CVE-2025-12595CRITICAL9.8A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /gofor...
CVE-2025-12594HIGH7.2A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown...
CVE-2025-12593HIGH7.2A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u...
CVE-2025-12603CRITICAL9.8/etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12602CRITICAL9.8/etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1...
CVE-2025-12601HIGH7.5Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12600CRITICAL9.8Web UI Malfunction when setting unexpected locale via API.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1...
CVE-2025-12599CRITICAL9.8Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-I...
CVE-2025-36367HIGH8.8IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz...
CVE-2025-6990HIGH8.8The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via ...
CVE-2025-6988MEDIUM6.4The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a...
CVE-2025-6574HIGH8.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-12171HIGH8.8The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va...
CVE-2025-12137MEDIUM4.9The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Re...
CVE-2025-11755HIGH8.8The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar...
CVE-2025-11499CRITICAL9.8The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ...
CVE-2025-10487HIGH7.3The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up t...
CVE-2025-12180MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T...
CVE-2025-12090MEDIUM6.4The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-12038MEDIUM4.3The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability c...
CVE-2025-11983MEDIUM4.3The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9....
CVE-2025-11740MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to...
CVE-2025-11502MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now