2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12094MEDIUM5.3The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to...
CVE-2025-8385MEDIUM6.8The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du...
CVE-2025-6520CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BA...
CVE-2025-10897HIGH8.6The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi...
CVE-2025-8489CRITICAL9.8The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vu...
CVE-2025-7846HIGH8.8The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-63675HIGH8.8cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt...
CVE-2025-5397CRITICAL9.8The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8....
CVE-2025-58152MEDIUM6.9FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i...
CVE-2025-54763HIGH8.6FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user...
CVE-2025-11191MEDIUM5.3The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the cr...
CVE-2025-11975MEDIUM4.3The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)...
CVE-2025-11806MEDIUM6.4The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver...
CVE-2025-23050LOW3.1QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (o...
CVE-2025-8849HIGH7.5LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api...
CVE-2025-6176HIGH7.5Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio...
CVE-2025-52665CRITICAL10A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat...
CVE-2025-52664HIGH8.8SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo...
CVE-2025-52663HIGH7.3A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention...
CVE-2025-48984HIGH8.8A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2025-48983CRITICAL9.9A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the ...
CVE-2025-48982HIGH7.8This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator ...
CVE-2025-48980MEDIUM6.5In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split Vie...
CVE-2025-27208MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker c...
CVE-2025-34298HIGH8.8Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now