2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2577 | MEDIUM | 6.4 | 0.3% | Mar 22, 2025 | The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi... |
| CVE-2025-2331 | MEDIUM | 6.5 | 0.4% | Mar 22, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2025-1973 | MEDIUM | 4.9 | 0.7% | Mar 22, 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, an... |
| CVE-2025-1972 | MEDIUM | 6.5 | 0.4% | Mar 22, 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici... |
| CVE-2025-2616 | MEDIUM | 4.8 | 0.3% | Mar 22, 2025 | A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown ... |
| CVE-2025-2484 | MEDIUM | 6.1 | 0.3% | Mar 22, 2025 | The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_i... |
| CVE-2025-2482 | MEDIUM | 6.1 | 0.3% | Mar 22, 2025 | The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' p... |
| CVE-2025-2479 | MEDIUM | 6.1 | 0.3% | Mar 22, 2025 | The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter i... |
| CVE-2025-2478 | MEDIUM | 4.9 | 0.4% | Mar 22, 2025 | The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versi... |
| CVE-2025-2477 | MEDIUM | 4.7 | 0.3% | Mar 22, 2025 | The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all vers... |
| CVE-2025-1311 | MEDIUM | 6.5 | 0.4% | Mar 22, 2025 | The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' para... |
| CVE-2025-0807 | MEDIUM | 4.3 | 0.1% | Mar 22, 2025 | The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S... |
| CVE-2025-1408 | MEDIUM | 4.3 | 0.3% | Mar 22, 2025 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-0723 | MEDIUM | 6.5 | 0.4% | Mar 22, 2025 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL I... |
| CVE-2025-2610 | MEDIUM | 5.4 | 0.9% | Mar 21, 2025 | Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module ... |
| CVE-2025-2609 | MEDIUM | 6.1 | 1.1% | Mar 21, 2025 | Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging ... |
| CVE-2025-26500 | MEDIUM | 4.6 | 0.2% | Mar 21, 2025 | : Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation... |
| CVE-2025-2607 | MEDIUM | 6.3 | 0.4% | Mar 21, 2025 | A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected b... |
| CVE-2025-2606 | MEDIUM | 6.3 | 0.3% | Mar 21, 2025 | A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affec... |
| CVE-2025-2604 | MEDIUM | 6.3 | 0.3% | Mar 21, 2025 | A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as... |
| CVE-2025-2603 | MEDIUM | 6.3 | 0.3% | Mar 21, 2025 | A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical... |
| CVE-2025-25036 | MEDIUM | 6.8 | 0.4% | Mar 21, 2025 | Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue ... |
| CVE-2025-29227 | MEDIUM | 6.3 | 0.7% | Mar 21, 2025 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtim... |
| CVE-2025-29226 | MEDIUM | 6.3 | 0.7% | Mar 21, 2025 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtim... |
| CVE-2025-29223 | MEDIUM | 6.3 | 0.7% | Mar 21, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRou... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now