2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48100CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbu...
CVE-2025-9376MEDIUM6.5The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to...
CVE-2025-39496CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Produ...
CVE-2025-55175MEDIUM6.1QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can...
CVE-2025-54544MEDIUM4.8QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attack...
CVE-2025-54543MEDIUM4.8QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker...
CVE-2025-54542MEDIUM5.5QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser hist...
CVE-2025-54541MEDIUM4.3QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft specia...
CVE-2025-54540MEDIUM6.1QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can cra...
CVE-2025-48963HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2025-58081HIGH8.7Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allo...
CVE-2025-58072HIGH8.7Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear...
CVE-2025-54819HIGH7.1Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear...
CVE-2025-54762CRITICAL9.8SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb...
CVE-2025-53970CRITICAL9.8SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb...
CVE-2025-53396HIGH7.3Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0....
CVE-2025-52460MEDIUM6.9Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a...
CVE-2025-46409HIGH8.7Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If thi...
CVE-2025-58322HIGH7.8NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM ...
CVE-2025-8073MEDIUM6.4The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-6255MEDIUM6.4The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-7956MEDIUM5.3The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in it...
CVE-2025-7955CRITICAL9.8The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi...
CVE-2025-8977MEDIUM6.5The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in al...
CVE-2025-9346MEDIUM6.4The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now