2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9345MEDIUM4.9The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versio...
CVE-2025-8603MEDIUM6.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge...
CVE-2025-0951MEDIUM4.3Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capa...
CVE-2025-9352MEDIUM5.4The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in ...
CVE-2025-9344MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2025-8897MEDIUM6.1The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2025-7812HIGH8.8The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-57845Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-34158. Reason: This candidate is a reservation d...
CVE-2025-36003MEDIUM5.3IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information whe...
CVE-2025-34523CRITICAL9.8A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data...
CVE-2025-34522CRITICAL9.8A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). ...
CVE-2025-34521MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection...
CVE-2025-34520CRITICAL9.8An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai...
CVE-2025-34163CRITICAL10Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce ...
CVE-2025-34162CRITICAL9.3An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Eme...
CVE-2025-34160CRITICAL10AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port...
CVE-2025-40779HIGH7.5If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the clien...
CVE-2025-5101MEDIUM5An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1...
CVE-2025-55618HIGH7.3In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field i...
CVE-2025-55582MEDIUM6.6D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly ...
CVE-2025-4225HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18....
CVE-2025-3601MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18....
CVE-2025-2246MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1...
CVE-2025-58050CRITICAL9.1The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b...
CVE-2025-55495MEDIUM6.5Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now