2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47343HIGH7.8Memory corruption while processing a video session to set video parameters.
CVE-2025-47339HIGH7.8Memory corruption while deinitializing a HDCP session.
CVE-2025-32300HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studi...
CVE-2025-31643HIGH8.8Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC...
CVE-2025-15472HIGH7.3A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of ...
CVE-2025-15158HIGH8.8The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in ...
CVE-2025-14835HIGH7.1The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet...
CVE-2025-14804HIGH7.7The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the fil...
CVE-2025-14070HIGH7.5The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-13801HIGH7.5The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t...
CVE-2025-13493HIGH7.5The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a...
CVE-2025-13371HIGH8.6The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-11877HIGH7.5The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed...
CVE-2025-11235HIGH7.5Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO...
CVE-2025-31642HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU...
CVE-2025-30631HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerc...
CVE-2025-29004HIGH8.8Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re...
CVE-2025-32304HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-15382HIGH8.1A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote att...
CVE-2025-69356HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69351HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni...
CVE-2025-69342HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69086HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69085HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank ...
CVE-2025-69084HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now