2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4643MEDIUM6.3Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker wh...
CVE-2025-8150MEDIUM6.4The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewr...
CVE-2025-54777MEDIUM5.3Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai...
CVE-2025-9441MEDIUM6.5The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all ve...
CVE-2025-9374MEDIUM4.3The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-8619MEDIUM6.4The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map ...
CVE-2025-8290MEDIUM6.4The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver...
CVE-2025-8147MEDIUM4.3The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th...
CVE-2025-53508HIGH8.6Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS c...
CVE-2025-53507HIGH7.1Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploit...
CVE-2025-9639HIGH8.7The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attacker...
CVE-2025-9619MEDIUM6.9A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of...
CVE-2025-9610CRITICAL9.8A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown process...
CVE-2025-9609HIGH8.8A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educac...
CVE-2025-8861CRITICAL9.8TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read,...
CVE-2025-8858HIGH8.7Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers t...
CVE-2025-8857CRITICAL9.8Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to ...
CVE-2025-9608HIGH8.8A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Formu...
CVE-2025-9607HIGH8.8A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the fil...
CVE-2025-9606HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionali...
CVE-2025-9605CRITICAL9.8A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControl...
CVE-2025-58333Rejected reason: Not used
CVE-2025-58332Rejected reason: Not used
CVE-2025-58331Rejected reason: Not used
CVE-2025-58330Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now