2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-29366CRITICAL9.8In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, w...
CVE-2025-29365CRITICAL9.8spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.
CVE-2025-55573HIGH8.8QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-36042MEDIUM5.4IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenti...
CVE-2025-33120HIGH7.8IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure...
CVE-2025-51825MEDIUM6.5JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/...
CVE-2025-50691MEDIUM5.3MCSManager 10.5.3 daemon process runs as a root account by default, and its sensitive data (including tokens and termina...
CVE-2025-38618HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It ...
CVE-2025-38617MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and pac...
CVE-2025-38616HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL...
CVE-2025-9331MEDIUM4.3The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2025-9259HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9258HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9257HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9256HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9255HIGH8.7WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitr...
CVE-2025-9254CRITICAL9.8WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log ...
CVE-2025-57896MEDIUM5.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc...
CVE-2025-57895MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss...
CVE-2025-57894MEDIUM4.3Missing Authorization vulnerability in ollybach WPPizza wppizza allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-57893MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Re...
CVE-2025-57892MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross...
CVE-2025-57891MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurr...
CVE-2025-57890MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sess...
CVE-2025-57888MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NooTheme Jobmonster noo-jobm...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now