2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7721CRITICAL9.8The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Incl...
CVE-2025-49641MEDIUM4.3A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refre...
CVE-2025-40636CRITICAL9.3SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retri...
CVE-2025-27237HIGH7.3In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged ...
CVE-2025-27236MEDIUM6.5A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have ...
CVE-2025-27231MEDIUM4.9The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host...
CVE-2025-10726CRITICAL9.1The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a...
CVE-2025-10582HIGH8.8The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and ...
CVE-2025-10547CRITICAL9.8An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all...
CVE-2025-10311MEDIUM4.3The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-10309MEDIUM4.3The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-10306LOW3.8The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version...
CVE-2025-10302MEDIUM4.3The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-10212MEDIUM5.3The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2025-10192MEDIUM6.4The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' sh...
CVE-2025-10165MEDIUM6.4The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back'...
CVE-2025-10053MEDIUM4.4The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings...
CVE-2025-0876MEDIUM4.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi A...
CVE-2025-11234HIGH7.5A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc...
CVE-2025-6388CRITICAL9.8The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1...
CVE-2025-11223HIGH8.4Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead ...
CVE-2025-0616HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center ...
CVE-2025-61671Rejected reason: Further research determined the issue is not an open source vulnerability.
CVE-2025-61599MEDIUM5.4Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitte...
CVE-2025-61597MEDIUM5.4Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now