2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58295MEDIUM5.5Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may aff...
CVE-2025-58292MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58291MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58290MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58288MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-58287MEDIUM5.5Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect servi...
CVE-2025-58286MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av...
CVE-2025-11594MEDIUM5.5A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f...
CVE-2025-11518MEDIUM5.3The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver...
CVE-2025-11254MEDIUM4.3The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in ...
CVE-2025-11167MEDIUM4.7The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulner...
CVE-2025-9496MEDIUM6.4The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modifie...
CVE-2025-9196MEDIUM5.3The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to S...
CVE-2025-11533CRITICAL9.8The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. T...
CVE-2025-11197MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ...
CVE-2025-10185MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderb...
CVE-2025-10048MEDIUM4.9The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up...
CVE-2025-11593HIGH8.8A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin...
CVE-2025-11592HIGH8.8A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edi...
CVE-2025-11591HIGH8.8A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknow...
CVE-2025-58285MEDIUM5.5Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service c...
CVE-2025-58284MEDIUM5.5Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service...
CVE-2025-58283MEDIUM5.5Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service c...
CVE-2025-58282MEDIUM5.5Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service ...
CVE-2025-58278MEDIUM5.5Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now