2025 CVE Vulnerabilities

45,252 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9500MEDIUM6.4The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in ...
CVE-2025-9499MEDIUM6.4The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library short...
CVE-2025-54946CRITICAL9.8A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to exe...
CVE-2025-54945CRITICAL9.8An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allow...
CVE-2025-54944CRITICAL9.8An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 1...
CVE-2025-54943CRITICAL9.8A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attacker...
CVE-2025-54942CRITICAL9.8A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11...
CVE-2025-9618MEDIUM4.3The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-4956MEDIUM4.3Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This ...
CVE-2025-34165HIGH8.8A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, una...
CVE-2025-34164CRITICAL9.3A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unau...
CVE-2025-58159HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was i...
CVE-2025-9678CRITICAL9.8A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown functi...
CVE-2025-58160LOW2.3tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior ...
CVE-2025-58157HIGH7.5gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerabilit...
CVE-2025-58156MEDIUM4.3Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authe...
CVE-2025-58068CRITICAL9.1Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable ...
CVE-2025-57822HIGH8.2Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next()...
CVE-2025-57752MEDIUM6.2Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to bef...
CVE-2025-55173MEDIUM4.3Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to bef...
CVE-2025-9677MEDIUM5.5A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown functi...
CVE-2025-9676MEDIUM5.5A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidMa...
CVE-2025-9675MEDIUM5.5A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file ...
CVE-2025-9674MEDIUM5.5A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functio...
CVE-2025-58067MEDIUM4.2Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now