2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52054MEDIUM5.3An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The roo...
CVE-2025-9578HIGH7.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2025-51972MEDIUM6.5A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to impro...
CVE-2025-51971MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Adv...
CVE-2025-51969MEDIUM6.5A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This...
CVE-2025-51968MEDIUM6.5A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The a...
CVE-2025-51967MEDIUM6.1A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Manag...
CVE-2025-58127MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercep...
CVE-2025-58126MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept tr...
CVE-2025-58125MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to interce...
CVE-2025-58124MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept t...
CVE-2025-58123MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept...
CVE-2025-54742HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2025-54738CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Auth...
CVE-2025-54734MEDIUM5.8Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-54733MEDIUM6.5Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting ...
CVE-2025-54731HIGH8.1Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showc...
CVE-2025-54725CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.Th...
CVE-2025-54724HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo al...
CVE-2025-54720CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest A...
CVE-2025-54716HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54714HIGH7.1Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incor...
CVE-2025-54710HIGH7.1Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Co...
CVE-2025-54029HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce cs...
CVE-2025-53588HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now