2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58601MEDIUM4.3Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly C...
CVE-2025-58600MEDIUM5.3Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting ...
CVE-2025-58599MEDIUM4.3Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocom...
CVE-2025-58598MEDIUM6.6Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce k...
CVE-2025-58597MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorre...
CVE-2025-58596MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction Mai...
CVE-2025-58594MEDIUM4.3Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-58593MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fo...
CVE-2025-58460MEDIUM4.2A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Over...
CVE-2025-58459MEDIUM4.3Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endp...
CVE-2025-58458MEDIUM4.3In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ b...
CVE-2025-57151HIGH8.8phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the ...
CVE-2025-57150HIGH7.2phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php v...
CVE-2025-57149MEDIUM6.5phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid paramete...
CVE-2025-57148CRITICAL9.1phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the la...
CVE-2025-57147HIGH7.5A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack ...
CVE-2025-57146HIGH8.1phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobi...
CVE-2025-57052CRITICAL9.8cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c...
CVE-2025-56608MEDIUM4.2The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHtt...
CVE-2025-9822MEDIUM5.5SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that ...
CVE-2025-47421HIGH8.6Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREEN...
CVE-2025-2416HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypa...
CVE-2025-26210HIGH8.8DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepsee...
CVE-2025-0878MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Li...
CVE-2025-9901MEDIUM5.9A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now