2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47339HIGH7.8Memory corruption while deinitializing a HDCP session.
CVE-2025-32300HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studi...
CVE-2025-31643HIGH8.8Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC...
CVE-2025-15472HIGH7.3A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of ...
CVE-2025-15158HIGH8.8The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in ...
CVE-2025-14835HIGH7.1The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet...
CVE-2025-14804HIGH7.7The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the fil...
CVE-2025-14070HIGH7.5The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-13801HIGH7.5The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t...
CVE-2025-13493HIGH7.5The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a...
CVE-2025-13371HIGH8.6The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-11877HIGH7.5The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed...
CVE-2025-11235HIGH7.5Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO...
CVE-2025-31642HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU...
CVE-2025-30631HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerc...
CVE-2025-29004HIGH8.8Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re...
CVE-2025-32304HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-15382HIGH8.1A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote att...
CVE-2025-69356HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69351HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni...
CVE-2025-69342HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69086HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69085HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank ...
CVE-2025-69084HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga...
CVE-2025-69083HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now