2025 CVE Vulnerabilities

45,225 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39929MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_neg...
CVE-2025-9952MEDIUM6.1The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to R...
CVE-2025-9886MEDIUM4.3The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to C...
CVE-2025-10383MEDIUM6.4The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-9485CRITICAL9.8The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptograph...
CVE-2025-9243HIGH8.1The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa...
CVE-2025-9030MEDIUM5.4The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label'...
CVE-2025-9029MEDIUM4.3The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres...
CVE-2025-8726MEDIUM5.4The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including,...
CVE-2025-61962MEDIUM5.9In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed...
CVE-2025-61895Rejected reason: Not used
CVE-2025-61894Rejected reason: Not used
CVE-2025-61893Rejected reason: Not used
CVE-2025-61892Rejected reason: Not used
CVE-2025-61891Rejected reason: Not used
CVE-2025-61890Rejected reason: Not used
CVE-2025-61889Rejected reason: Not used
CVE-2025-61888Rejected reason: Not used
CVE-2025-61887Rejected reason: Not used
CVE-2025-11228MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-11227MEDIUM6.5The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ...
CVE-2025-10746MEDIUM6.5The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and incl...
CVE-2025-10751HIGH7.8MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi...
CVE-2025-61685MEDIUM6.5Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vuln...
CVE-2025-61681MEDIUM5.4KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its fi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now