2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8423MEDIUM5.4The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-8422HIGH7.5The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all ver...
CVE-2025-8417HIGH8.1The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, ...
CVE-2025-8398MEDIUM6.4The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode...
CVE-2025-8392MEDIUM6.4The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all...
CVE-2025-8318MEDIUM6.4The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions...
CVE-2025-8316MEDIUM6.4The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all ver...
CVE-2025-8215MEDIUM6.4The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widge...
CVE-2025-5801MEDIUM6.4The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter...
CVE-2025-0763MEDIUM4.3The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-8479MEDIUM4.3The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1....
CVE-2025-9059HIGH8.8The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hij...
CVE-2025-9034MEDIUM6.1The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user ...
CVE-2025-10247MEDIUM6.3A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of ...
CVE-2025-9910MEDIUM4.7Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeB...
CVE-2025-9776MEDIUM6.5The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Inje...
CVE-2025-10246LOW3.5A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b...
CVE-2025-10245MEDIUM4.3A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown function...
CVE-2025-10236HIGH7.5A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the...
CVE-2025-6088LOW3.1In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow una...
CVE-2025-10235MEDIUM4.8A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm o...
CVE-2025-10234MEDIUM4.8A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point...
CVE-2025-10233MEDIUM4.3A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the f...
CVE-2025-10232MEDIUM5.4A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the fil...
CVE-2025-10229MEDIUM4.3A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the file /api/v2/logout. Su...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now