2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-68885HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS...
CVE-2025-49354HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category recent-posts-f...
CVE-2025-49353HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path noindex-by-path allows Stored XSS.This i...
CVE-2025-49345HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue aff...
CVE-2025-49344HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This ...
CVE-2025-49343HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in socialprofilr Social Profilr social-profilr-display-social-network-pr...
CVE-2025-49342HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affec...
CVE-2025-13029HIGH7.5The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its RE...
CVE-2025-59137HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behan...
CVE-2025-49346HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allo...
CVE-2025-15375HIGH8.8A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/a...
CVE-2025-68131HIGH7.5cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting ...
CVE-2025-15371HIGH7.8A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. A...
CVE-2025-62753HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59131HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue...
CVE-2025-15360HIGH7.2A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd...
CVE-2025-66723HIGH7.5inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Librar...
CVE-2025-61594HIGH7.5URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Rub...
CVE-2025-15356HIGH8.8A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file ...
CVE-2025-69261HIGH7.5WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instan...
CVE-2025-69256HIGH7.5The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Sta...
CVE-2025-66835HIGH7.1TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary...
CVE-2025-66834HIGH7.3A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadshe...
CVE-2025-66824HIGH8.7A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference fun...
CVE-2025-15264HIGH7.3A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthum...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now