2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55971MEDIUM4.7TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to ...
CVE-2025-34226HIGH7.1OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field suppli...
CVE-2025-10729CRITICAL9.4The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creatio...
CVE-2025-10728CRITICAL9.4When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading t...
CVE-2025-60454MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis...
CVE-2025-60453MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis...
CVE-2025-60452MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis...
CVE-2025-60451MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis...
CVE-2025-60450MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis...
CVE-2025-60449MEDIUM4.9An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.p...
CVE-2025-60448MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due ...
CVE-2025-60447MEDIUM5.9A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in t...
CVE-2025-60445MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exis...
CVE-2025-59489HIGH7.4Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi...
CVE-2025-10609MEDIUM5.9Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within ...
CVE-2025-9945MEDIUM4.3The Optimize More! – CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-9897MEDIUM4.3The AP Background plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-9895MEDIUM4.3The Notification Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-9892MEDIUM5.3The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-9889MEDIUM4.3The ContentMX Content Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2025-9885MEDIUM4.3The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-9884MEDIUM6.1The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-9876MEDIUM6.4The Ird Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irdslider' shortcode ...
CVE-2025-9875MEDIUM6.4The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 't...
CVE-2025-9859MEDIUM6.4The Fintelligence Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fintell...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now