2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10193HIGH7.4DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protection...
CVE-2025-10251CRITICAL9.8A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/adm...
CVE-2025-9018HIGH8.8The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab...
CVE-2025-40696MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ...
CVE-2025-40695MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ...
CVE-2025-40694MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ...
CVE-2025-40693MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored ...
CVE-2025-40692CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40691CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40690CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40689CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40687CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-10250MEDIUM5A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function ...
CVE-2025-58321CRITICAL10Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
CVE-2025-58320HIGH7.3Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
CVE-2025-48041HIGH7.1Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive...
CVE-2025-48040MEDIUM6.9Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodi...
CVE-2025-48039MEDIUM5.3Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive...
CVE-2025-48038MEDIUM5.3Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive...
CVE-2025-9918HIGH8.7A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3....
CVE-2025-9874HIGH7.5The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2025-9861MEDIUM6.4The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts'...
CVE-2025-9860MEDIUM6.4The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in al...
CVE-2025-9855MEDIUM6.4The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_aut...
CVE-2025-9850MEDIUM6.4The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' sh...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now