2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11269MEDIUM5.3The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-11244LOW3.7The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version...
CVE-2025-11238HIGH7.2The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions ...
CVE-2025-10737MEDIUM6.4The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's short...
CVE-2025-10694MEDIUM5.3The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera...
CVE-2025-11823MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is...
CVE-2025-10579MEDIUM5.3The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due t...
CVE-2025-11760MEDIUM5.3The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposu...
CVE-2025-34503HIGH7Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker ...
CVE-2025-34502HIGH7Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. ...
CVE-2025-34500HIGH7Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit...
CVE-2025-12194MEDIUM5.9Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ...
CVE-2025-62711LOW3.1Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model r...
CVE-2025-4106HIGH8.9An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable ...
CVE-2025-34293HIGH8.6GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API...
CVE-2025-62723MEDIUM4.3FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user ca...
CVE-2025-62717CRITICAL9.1Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification co...
CVE-2025-60954HIGH8.3Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexit...
CVE-2025-52099Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-29088. Reason: This record is a duplicate of CVE-2025-...
CVE-2025-62716HIGH8.1Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_pa...
CVE-2025-60419MEDIUM6.2An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authentica...
CVE-2025-60735HIGH7.6PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
CVE-2025-60731HIGH7.6PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
CVE-2025-60730HIGH7.6PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
CVE-2025-60729MEDIUM5.3PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now