2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9463MEDIUM6.5The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v...
CVE-2025-9367MEDIUM5.5The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up...
CVE-2025-8778MEDIUM4.3The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-7843MEDIUM6.4The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u...
CVE-2025-7826MEDIUM6.5The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions ...
CVE-2025-7049HIGH8.8The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions u...
CVE-2025-6189MEDIUM6.5The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter ...
CVE-2025-41714HIGH8.8The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an ...
CVE-2025-10142MEDIUM4.9The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa...
CVE-2025-10126MEDIUM6.4The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short...
CVE-2025-10049HIGH7.2The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ...
CVE-2025-10040HIGH7.7The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of dat...
CVE-2025-10001HIGH7.2The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m...
CVE-2025-8388MEDIUM6.4The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-10197MEDIUM6.3A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability...
CVE-2025-10195MEDIUM5.3A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManif...
CVE-2025-59046CRITICAL9.8The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc...
CVE-2025-59044MEDIUM4.4Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs f...
CVE-2025-59042HIGH7PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being ap...
CVE-2025-59039CRITICAL9.3Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest we...
CVE-2025-59038HIGH8.6Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9...
CVE-2025-58750CRITICAL9.1rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58448CRITICAL9.8rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58447CRITICAL9.8rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-10172HIGH8.8A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/for...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now