2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5949HIGH8.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-12118MEDIUM6.4The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions ...
CVE-2025-11995HIGH7.2The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al...
CVE-2025-11927MEDIUM4.4The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-11377MEDIUM4.3The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,...
CVE-2025-12367MEDIUM4.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin...
CVE-2025-11928MEDIUM4.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-11833CRITICAL9.8The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to...
CVE-2025-62275MEDIUM5.3Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023....
CVE-2025-11922MEDIUM6.4The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individ...
CVE-2025-11920HIGH8.8The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14...
CVE-2025-11816MEDIUM5.3The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul...
CVE-2025-11174MEDIUM5.3The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and includ...
CVE-2025-62276MEDIUM5.5The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver...
CVE-2025-12464MEDIUM6.2A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped ...
CVE-2025-63563MEDIUM6.5Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions...
CVE-2025-63562MEDIUM6.3Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorizati...
CVE-2025-63561HIGH7.5Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Serv...
CVE-2025-60711MEDIUM6.3Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a n...
CVE-2025-10693HIGH7.6When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-...
CVE-2025-64349HIGH8.8ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, ...
CVE-2025-64348HIGH7.1ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the ...
CVE-2025-63458HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wi...
CVE-2025-63454HIGH7.5Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentContro...
CVE-2025-62618HIGH8.6ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now