2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41007CRITICAL9.3SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through...
CVE-2025-6229MEDIUM6.4The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl...
CVE-2025-13997MEDIUM5.3The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin f...
CVE-2025-10734MEDIUM5.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10731MEDIUM5.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10679HIGH7.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10736MEDIUM6.5The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-71276MEDIUM6.1SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
CVE-2025-14037HIGH8.1The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi...
CVE-2025-13910MEDIUM6.1The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJA...
CVE-2025-63261HIGH7.8AWStats 8.0 is vulnerable to Command Injection via the open function
CVE-2025-55988HIGH7.2An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire...
CVE-2025-63260MEDIUM5.4SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-U...
CVE-2025-62846MEDIUM6.7An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th...
CVE-2025-62845MEDIUM6.7An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l...
CVE-2025-62844MEDIUM5.5A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c...
CVE-2025-62843MEDIUM6.8An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. ...
CVE-2025-59383CRITICAL9.1A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi...
CVE-2025-15608CRITICAL9.8This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe ...
CVE-2025-15607CRITICAL9.8A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo...
CVE-2025-67260HIGH8.8The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln...
CVE-2025-46597HIGH7.5Bitcoin Core 0.13.0 through 29.x has an integer overflow.
CVE-2025-46598MEDIUM5.3Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
CVE-2025-67115MEDIUM6.5A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor...
CVE-2025-67114CRITICAL9.8Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now