2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11163MEDIUM4.3The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-11149HIGH7.5This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package...
CVE-2025-11148CRITICAL9.8All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha...
CVE-2025-10991HIGH7The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have ...
CVE-2025-10196MEDIUM6.4The Survey Anyplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'surveyanyplace_e...
CVE-2025-10191MEDIUM6.4The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-10189MEDIUM6.4The BP Direct Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bpdm_login' shor...
CVE-2025-10182MEDIUM6.4The dbview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dbview' shortcode in all ...
CVE-2025-10179MEDIUM6.4The My AskAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'myaskai' shortcode in a...
CVE-2025-10168MEDIUM6.4The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shor...
CVE-2025-10131MEDIUM6.4The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' sho...
CVE-2025-10130MEDIUM6.4The Layers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all ...
CVE-2025-10128MEDIUM6.4The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' ...
CVE-2025-10000MEDIUM6.4The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missin...
CVE-2025-61586MEDIUM5.3FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by s...
CVE-2025-59952HIGH8.7MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp...
CVE-2025-59950MEDIUM5.4FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking p...
CVE-2025-59948MEDIUM5.4FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attrib...
CVE-2025-59942HIGH7.5go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it v...
CVE-2025-59941MEDIUM6.5go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.8 and below, go-f3's justification ...
CVE-2025-59940MEDIUM6.5mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerabil...
CVE-2025-59937CRITICAL9.1go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of ...
CVE-2025-43817MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay ...
CVE-2025-43813HIGH8.2Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.10...
CVE-2025-43812MEDIUM5.4Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Lifera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now